CVE-2026-34367 is a Server-Side Request Forgery (SSRF) vulnerability in InvoiceShelf, an open-source web & mobile app for expense tracking and invoicing. The vulnerability exists in the Invoice PDF generation module. User-supplied HTML in the invoice Notes field is passed unsanitized to the Dompdf rendering library, which can fetch remote resources referenced in the markup. This can be triggered via the P [truncated]
A Server-Side Request Forgery (SSRF) vulnerability exists in InvoiceShelf, an open-source web & mobile app, prior to version 2.2.0. The vulnerability is located in the Payment receipt PDF generation module. User-supplied HTML in the payment Notes field is passed unsanitised to the Dompdf rendering library, which can fetch remote resources referenced in the markup. This issue allows for SSRF attacks direct [truncated]
A Server-Side Request Forgery (SSRF) vulnerability exists in InvoiceShelf, an open-source web & mobile app, prior to version 2.2.0. The vulnerability is located in the Estimate PDF generation module. User-supplied HTML in the estimate Notes field is passed unsanitized to the Dompdf rendering library, which can fetch remote resources referenced in the markup. This issue can be exploited directly via the PD [truncated]