These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
FOSSBilling, a free, open-source billing and client management system, has a vulnerability prior to version 0.8.1. The system stores downloadable product files using a deterministic filename-derived path, which can lead to file overwrites and unauthorized access. Administrators and users of FOSSBilling version prior to 0.8.1 should be aware of this vulnerability. The vulnerability class is related to inse [truncated]
The FOSSBilling system, a free, open-source billing and client management solution, contains a security vulnerability in versions 0.5.3 through 0.7.2. Specifically, the Guest `serviceapikey/get_info` API endpoint is accessible without proper authentication. This allows any caller with a valid API key to retrieve all custom configuration parameters stored in the key's database record. These custom fields, [truncated]
The FOSSBilling system, a free, open-source billing and client management solution, was found to have a vulnerability in versions 0.5.6 through 0.7.2. This issue pertains to the reuse of tokens for client password reset requests. When a 'ClientPasswordReset' record already exists for a client, subsequent calls to the 'reset_password' guest API endpoint would reuse the existing token instead of generating [truncated]
CVE-2026-53645 is a high-severity vulnerability in FOSSBilling versions prior to 0.8.0. The issue allows a low-privileged staff account to grant arbitrary module permissions to itself through the admin API, resulting in persistent privilege escalation. A staff user with only `staff.create_and_edit_staff` permission can call `/api/admin/staff/permissions_update` targeting their own account and write any pe [truncated]
CVE-2026-53644 is a high-severity vulnerability in FOSSBilling, a free, open-source billing and client management system. The vulnerability allows authenticated clients to read and reset API key service secrets for orders that are no longer in an active state. This is due to missing order-state validation in two client API endpoints. A fix is available in version 0.8.0. The root cause is the lack of order [truncated]
CVE-2026-53643 is a high-severity vulnerability in FOSSBilling, a free, open-source billing and client management system. The vulnerability allows low-privileged staff accounts to perform unauthorized actions via admin API endpoints due to a combination of the `can_always_access` module flag and insufficient permission checks or unsafe parameter handling on individual endpoints. The issue was fixed in ver [truncated]
A vulnerability was found in FOSSBilling versions 0.5.6 through 0.7.2. When the 'Require Email Confirmation' setting is enabled, a logged-in client with an unverified email address can access all client-area pages and read real account data, including wallet balances and transaction history. The issue is due to overly permissive page-side enforcement, allowing any request whose path starts with '/client'. [truncated]
CVE-2026-53641 is a stored cross-site scripting (XSS) vulnerability in FOSSBilling, a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 are affected. The vulnerability allows an attacker with admin access to inject malicious JavaScript payloads into email content, which execute in the browser of any client who views their email history. The vulnerability has a CVSS score [truncated]
CVE-2026-53640 is a vulnerability in FOSSBilling, a free, open-source billing and client management system. Low-privileged staff accounts may read sensitive data via admin API endpoints that lack permission checks. The issue was addressed in version 0.8.0. Users should update to the latest version and restrict staff accounts to only those who need access to sensitive data. This vulnerability has a CVSS sc [truncated]
CVE-2026-43927 is a race condition vulnerability in the cart checkout flow of FOSSBilling, a free, open-source billing and client management system. The issue allows an authenticated client to apply a promo code beyond its configured maximum uses by sending concurrent checkout requests. This can result in unlimited discounted or free orders from a single-use or limited-use promo code. The vulnerability wa [truncated]
CVE-2026-43925 is a medium-severity vulnerability in FOSSBilling, a free, open-source billing and client management system. An unauthenticated mass assignment vulnerability in the client self-registration endpoint allows any visitor to assign themselves to an arbitrary client group during sign-up. This could enable an attacker to apply group-restricted discount codes and receive unauthorized discounts. Th [truncated]
CVE-2026-43921 is a PHP code injection vulnerability in FOSSBilling's `Config::prettyPrintArrayToPHP()` method. Versions 0.6.10 through 0.7.2 are affected. An attacker with admin privileges can inject arbitrary PHP code that executes on every subsequent request. This could lead to unauthorized code execution, data breaches, or system compromise. Version 0.8.0 contains a patch. Some workarounds are availab [truncated]
CVE-2026-43918 is a high-severity vulnerability in FOSSBilling, a free, open-source billing and client management system. The issue allows suspended or deactivated users to retain full access due to improper session invalidation. This vulnerability affects FOSSBilling versions prior to 0.8.0. Users with administrative privileges should be aware of this vulnerability and take immediate action.
CVE-2026-42341 is an unauthenticated payment bypass vulnerability in FOSSBilling's IPN callback endpoint. Versions 0.6.0 through 0.7.2 are affected when the Custom payment adapter is enabled. An attacker can mark any unpaid invoice as paid and credit the associated client account without making an actual payment by sending a single crafted HTTP request. Version 0.8.0 patches the issue. Some workarounds ar [truncated]
CVE-2026-42331 is a high-severity vulnerability in FOSSBilling, a free, open-source billing and client management system. The vulnerability exists in the Guest API invoice/update endpoint, which lacks an authorization check present in other invoice-related endpoints. This omission allows an unauthenticated user with knowledge of an invoice hash to modify the payment gateway associated with an unpaid invoice.
CVE-2026-33734 is a SQL injection vulnerability in the `Massmailer` module filter functionality of FOSSBilling versions 0.6.0 through 0.7.2. An authenticated administrator can supply crafted filter values when updating a mass email message, causing untrusted input to be interpolated directly into SQL in the recipient selection query. The vulnerability was patched in version 0.8.0. Some workarounds are ava [truncated]
CVE-2026-27604 is a critical authorization bypass vulnerability in FOSSBilling, a free, open-source billing and client management system. The vulnerability allows unauthenticated access to privileged `/api/system/*` endpoints, enabling attackers to invoke admin API methods without valid credentials, session, or CSRF token. FOSSBilling version 0.8.0 patches the issue. Some workarounds are available, includ [truncated]
CVE-2026-43926 is a MEDIUM severity vulnerability in FOSSBilling, a free, open-source billing and client management system. The vulnerability allows an attacker to bypass the rate limiter and probe the password reset confirmation endpoint for valid reset tokens without any per-IP request limiting, attempt counting, or lockout mechanism. This is possible because the password reset confirmation endpoint `/c [truncated]