PatchSiren

InvoiceShelf CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH InvoiceShelf CVE published 2026-03-31

CVE-2026-34365

A Server-Side Request Forgery (SSRF) vulnerability exists in InvoiceShelf, an open-source web & mobile app, prior to version 2.2.0. The vulnerability is located in the Estimate PDF generation module. User-supplied HTML in the estimate Notes field is passed unsanitized to the Dompdf rendering library, which can fetch remote resources referenced in the markup. This issue can be exploited directly via the PD [truncated]