PatchSiren

invoiceninja CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH invoiceninja CVE published 2026-08-05

CVE-2026-71233

InvoiceNinja v5-stable is affected by a stored cross-site scripting (XSS) vulnerability. An authenticated user with invoice creation access can exploit this by setting the 'terms' field to an HTML/JavaScript payload that executes in the client's browser when they view the invoice. This allows for session cookie theft and client account takeover. The vulnerability exists due to the lack of HTML sanitizatio [truncated]