Solidinvoice

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 13
    Known Exploited: 0
    0
    Critical Level Threats
    3
    High Level Threats
    5
    Medium Level Threats
    5
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-61688

    SolidInvoice allows cross-user access to API token request history via writable DataGrid LiveComponent props

    Last Modified: Sep 04, 2026
    Published: Sep 04, 2026

    CVE-2026-61614

    SolidInvoice's long-lived API tokens accepted as URL query parameters, exposing credentials in server logs and browser history

    Last Modified: Sep 04, 2026
    Published: Sep 04, 2026

    CVE-2026-61608

    SolidInvoice's user invitation tokens have no expiry, allowing indefinite unauthorized company access via leaked or old invitation links

    Last Modified: Sep 04, 2026
    Published: Sep 04, 2026

    CVE-2026-61686

    SolidInvoice: PHP unserialize() called on client-controlled data in DataGrid LiveComponent context prop

    Last Modified: Sep 04, 2026
    Published: Sep 04, 2026

    CVE-2026-46489

    SolidInvoice: Unrestricted file upload with no MIME validation allows stored XSS via malicious SVG logo

    Last Modified: Jun 12, 2026
    Published: Jun 11, 2026
    Items Per Page