PatchSiren

InvoiceShelf CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH InvoiceShelf CVE published 2026-03-31

CVE-2026-34367

CVE-2026-34367 is a Server-Side Request Forgery (SSRF) vulnerability in InvoiceShelf, an open-source web & mobile app for expense tracking and invoicing. The vulnerability exists in the Invoice PDF generation module. User-supplied HTML in the invoice Notes field is passed unsanitized to the Dompdf rendering library, which can fetch remote resources referenced in the markup. This can be triggered via the P [truncated]

HIGH InvoiceShelf CVE published 2026-03-31

CVE-2026-34366

A Server-Side Request Forgery (SSRF) vulnerability exists in InvoiceShelf, an open-source web & mobile app, prior to version 2.2.0. The vulnerability is located in the Payment receipt PDF generation module. User-supplied HTML in the payment Notes field is passed unsanitised to the Dompdf rendering library, which can fetch remote resources referenced in the markup. This issue allows for SSRF attacks direct [truncated]

HIGH InvoiceShelf CVE published 2026-03-31

CVE-2026-34365

A Server-Side Request Forgery (SSRF) vulnerability exists in InvoiceShelf, an open-source web & mobile app, prior to version 2.2.0. The vulnerability is located in the Estimate PDF generation module. User-supplied HTML in the estimate Notes field is passed unsanitized to the Dompdf rendering library, which can fetch remote resources referenced in the markup. This issue can be exploited directly via the PD [truncated]