This issue affects Invoice Ninja: from 5.8.56 through 5.11.23.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-1699 | Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the application user. This issue affects Invoice Ninja: from 5.8.56 through 5.11.23. |
Wed, 19 Nov 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Invoiceninja
Invoiceninja invoice Ninja |
|
| CPEs | cpe:2.3:a:invoiceninja:invoice_ninja:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Invoiceninja
Invoiceninja invoice Ninja |
Wed, 12 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Jan 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the application user. This issue affects Invoice Ninja: from 5.8.56 through 5.11.23. | |
| Title | Invoice Ninja PDF Rendering Server Side Request Forgery | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-11-19T20:29:57.454Z
Reserved: 2025-01-14T17:02:11.906Z
Link: CVE-2025-0474
Updated: 2025-02-12T20:25:34.257Z
Status : Deferred
Published: 2025-01-14T19:15:32.930
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-0474
No data.
OpenCVE Enrichment
No data.
EUVD