PatchSiren

FOSSBilling CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM FOSSBilling CVE published 2026-07-07

CVE-2026-53648

FOSSBilling, a free, open-source billing and client management system, has a vulnerability prior to version 0.8.1. The system stores downloadable product files using a deterministic filename-derived path, which can lead to file overwrites and unauthorized access. Administrators and users of FOSSBilling version prior to 0.8.1 should be aware of this vulnerability. The vulnerability class is related to inse [truncated]

MEDIUM FOSSBilling CVE published 2026-07-07

CVE-2026-53647

The FOSSBilling system, a free, open-source billing and client management solution, contains a security vulnerability in versions 0.5.3 through 0.7.2. Specifically, the Guest `serviceapikey/get_info` API endpoint is accessible without proper authentication. This allows any caller with a valid API key to retrieve all custom configuration parameters stored in the key's database record. These custom fields, [truncated]

HIGH FOSSBilling CVE published 2026-07-06

CVE-2026-53646

The FOSSBilling system, a free, open-source billing and client management solution, was found to have a vulnerability in versions 0.5.6 through 0.7.2. This issue pertains to the reuse of tokens for client password reset requests. When a 'ClientPasswordReset' record already exists for a client, subsequent calls to the 'reset_password' guest API endpoint would reuse the existing token instead of generating [truncated]

HIGH FOSSBilling CVE published 2026-07-06

CVE-2026-53645

CVE-2026-53645 is a high-severity vulnerability in FOSSBilling versions prior to 0.8.0. The issue allows a low-privileged staff account to grant arbitrary module permissions to itself through the admin API, resulting in persistent privilege escalation. A staff user with only `staff.create_and_edit_staff` permission can call `/api/admin/staff/permissions_update` targeting their own account and write any pe [truncated]

HIGH FOSSBilling CVE published 2026-07-06

CVE-2026-53644

CVE-2026-53644 is a high-severity vulnerability in FOSSBilling, a free, open-source billing and client management system. The vulnerability allows authenticated clients to read and reset API key service secrets for orders that are no longer in an active state. This is due to missing order-state validation in two client API endpoints. A fix is available in version 0.8.0. The root cause is the lack of order [truncated]

HIGH FOSSBilling CVE published 2026-07-06

CVE-2026-53643

CVE-2026-53643 is a high-severity vulnerability in FOSSBilling, a free, open-source billing and client management system. The vulnerability allows low-privileged staff accounts to perform unauthorized actions via admin API endpoints due to a combination of the `can_always_access` module flag and insufficient permission checks or unsafe parameter handling on individual endpoints. The issue was fixed in ver [truncated]

MEDIUM FOSSBilling CVE published 2026-07-06

CVE-2026-53642

A vulnerability was found in FOSSBilling versions 0.5.6 through 0.7.2. When the 'Require Email Confirmation' setting is enabled, a logged-in client with an unverified email address can access all client-area pages and read real account data, including wallet balances and transaction history. The issue is due to overly permissive page-side enforcement, allowing any request whose path starts with '/client'. [truncated]

MEDIUM FOSSBilling CVE published 2026-07-06

CVE-2026-53641

CVE-2026-53641 is a stored cross-site scripting (XSS) vulnerability in FOSSBilling, a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 are affected. The vulnerability allows an attacker with admin access to inject malicious JavaScript payloads into email content, which execute in the browser of any client who views their email history. The vulnerability has a CVSS score [truncated]

LOW FOSSBilling CVE published 2026-07-06

CVE-2026-53640

CVE-2026-53640 is a vulnerability in FOSSBilling, a free, open-source billing and client management system. Low-privileged staff accounts may read sensitive data via admin API endpoints that lack permission checks. The issue was addressed in version 0.8.0. Users should update to the latest version and restrict staff accounts to only those who need access to sensitive data. This vulnerability has a CVSS sc [truncated]

MEDIUM FOSSBilling CVE published 2026-07-06

CVE-2026-43927

CVE-2026-43927 is a race condition vulnerability in the cart checkout flow of FOSSBilling, a free, open-source billing and client management system. The issue allows an authenticated client to apply a promo code beyond its configured maximum uses by sending concurrent checkout requests. This can result in unlimited discounted or free orders from a single-use or limited-use promo code. The vulnerability wa [truncated]

MEDIUM FOSSBilling CVE published 2026-07-06

CVE-2026-43925

CVE-2026-43925 is a medium-severity vulnerability in FOSSBilling, a free, open-source billing and client management system. An unauthenticated mass assignment vulnerability in the client self-registration endpoint allows any visitor to assign themselves to an arbitrary client group during sign-up. This could enable an attacker to apply group-restricted discount codes and receive unauthorized discounts. Th [truncated]

HIGH FOSSBilling CVE published 2026-07-06

CVE-2026-43921

CVE-2026-43921 is a PHP code injection vulnerability in FOSSBilling's `Config::prettyPrintArrayToPHP()` method. Versions 0.6.10 through 0.7.2 are affected. An attacker with admin privileges can inject arbitrary PHP code that executes on every subsequent request. This could lead to unauthorized code execution, data breaches, or system compromise. Version 0.8.0 contains a patch. Some workarounds are availab [truncated]

HIGH FOSSBilling CVE published 2026-07-06

CVE-2026-43918

CVE-2026-43918 is a high-severity vulnerability in FOSSBilling, a free, open-source billing and client management system. The issue allows suspended or deactivated users to retain full access due to improper session invalidation. This vulnerability affects FOSSBilling versions prior to 0.8.0. Users with administrative privileges should be aware of this vulnerability and take immediate action.

CRITICAL FOSSBilling CVE published 2026-07-06

CVE-2026-42341

CVE-2026-42341 is an unauthenticated payment bypass vulnerability in FOSSBilling's IPN callback endpoint. Versions 0.6.0 through 0.7.2 are affected when the Custom payment adapter is enabled. An attacker can mark any unpaid invoice as paid and credit the associated client account without making an actual payment by sending a single crafted HTTP request. Version 0.8.0 patches the issue. Some workarounds ar [truncated]

HIGH FOSSBilling CVE published 2026-07-06

CVE-2026-42331

CVE-2026-42331 is a high-severity vulnerability in FOSSBilling, a free, open-source billing and client management system. The vulnerability exists in the Guest API invoice/update endpoint, which lacks an authorization check present in other invoice-related endpoints. This omission allows an unauthenticated user with knowledge of an invoice hash to modify the payment gateway associated with an unpaid invoice.

MEDIUM FOSSBilling CVE published 2026-07-06

CVE-2026-33734

CVE-2026-33734 is a SQL injection vulnerability in the `Massmailer` module filter functionality of FOSSBilling versions 0.6.0 through 0.7.2. An authenticated administrator can supply crafted filter values when updating a mass email message, causing untrusted input to be interpolated directly into SQL in the recipient selection query. The vulnerability was patched in version 0.8.0. Some workarounds are ava [truncated]

CRITICAL FOSSBilling CVE published 2026-06-23

CVE-2026-27604

CVE-2026-27604 is a critical authorization bypass vulnerability in FOSSBilling, a free, open-source billing and client management system. The vulnerability allows unauthenticated access to privileged `/api/system/*` endpoints, enabling attackers to invoke admin API methods without valid credentials, session, or CSRF token. FOSSBilling version 0.8.0 patches the issue. Some workarounds are available, includ [truncated]

MEDIUM FOSSBilling CVE published 2026-06-04

CVE-2026-43926

CVE-2026-43926 is a MEDIUM severity vulnerability in FOSSBilling, a free, open-source billing and client management system. The vulnerability allows an attacker to bypass the rate limiter and probe the password reset confirmation endpoint for valid reset tokens without any per-IP request limiting, attempt counting, or lockout mechanism. This is possible because the password reset confirmation endpoint `/c [truncated]