CVE-2024-56975
CVE-2024-56975 is a critical-severity vulnerability in Invoiceplane with a CVSS 3.x base score of 9.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-434.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- EPSS exploit prediction: 1% (48th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2024-54327
- Weakness: CWE-434
- Affected product: Invoiceplane
- Published:
- Last modified:
Description
InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method of the Upload controller.
Frequently asked questions
- What is CVE-2024-56975?
- InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method of the Upload controller.
- How severe is CVE-2024-56975?
- CVE-2024-56975 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2024-56975 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (48th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2024-56975?
- CVE-2024-56975 affects Invoiceplane. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2024-56975?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- Does CVE-2024-56975 have an EU (EUVD) identifier?
- Yes. CVE-2024-56975 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2024-54327.
- When was CVE-2024-56975 published?
- CVE-2024-56975 was published on 2025-03-28 and last updated on 2026-06-17.
References
- https://github.com/InvoicePlane/InvoicePlane/pull/1127
- https://github.com/InvoicePlane/InvoicePlane/pull/1166
Affected products (1)
- cpe:2.3:a:invoiceplane:invoiceplane:*:*:*:*:*:*:*:*
More vulnerabilities in Invoiceplane
- CVE-2025-67084 — Critical (CVSS 9.9): File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files…
- CVE-2026-25548 — Critical (CVSS 9.1): InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote…
- CVE-2017-1000238 — High (CVSS 8.8): InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a…
- CVE-2026-23491 — High (CVSS 7.5): InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A path traversal…
- CVE-2021-29024 — High (CVSS 7.5): In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing…
- CVE-2025-67082 — Medium (CVSS 6.5): An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity"…
All CVEs affecting Invoiceplane →
Other CWE-434 (Unrestricted Upload of File with Dangerous Type) vulnerabilities
- CVE-2026-75949 — Critical (CVSS 10.0): Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 -…
- CVE-2026-74803 — Critical (CVSS 10.0): Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts…
- CVE-2026-66665 — Critical (CVSS 10.0): Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
- CVE-2026-61900 — Critical (CVSS 10.0): Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla…
- CVE-2026-61424 — Critical (CVSS 10.0): Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla…
- CVE-2026-57719 — Critical (CVSS 10.0): Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using…
Browse all CWE-434 (Unrestricted Upload of File with Dangerous Type) vulnerabilities →