cbcvebase.

Sourcecodester Indian Invoicing System vulnerabilities

4 known vulnerabilities affecting sourcecodester/indian_invoicing_system.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM3LOW1

Vulnerabilities

Page 1 of 1
CVE-2026-9412P3MEDIUMCVSS 6.3v1.02026-05-25
CVE-2026-9412 [MEDIUM] CWE-266 CVE-2026-9412: A vulnerability was determined in SourceCodester Indian Invoicing System 1.0. Impacted is an unknown A vulnerability was determined in SourceCodester Indian Invoicing System 1.0. Impacted is an unknown function of the component Backend Endpoint. Executing a manipulation can lead to improper access controls. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. Multiple endpoints are affected.
cvelistv5nvd
CVE-2026-9411P3MEDIUMCVSS 6.3v1.02026-05-25
CVE-2026-9411 [MEDIUM] CWE-74 CVE-2026-9411: A vulnerability was found in SourceCodester Indian Invoicing System 1.0. This issue affects some unk A vulnerability was found in SourceCodester Indian Invoicing System 1.0. This issue affects some unknown processing of the file /Invoicing/IGST_Invoice.php of the component Invoice Generation Handler. Performing a manipulation of the argument customer_name/category results in sql injection. The attack can be initiated remotely. The exploit has been mad
cvelistv5nvd
CVE-2026-9413P4MEDIUMCVSS 4.3v1.02026-05-25
CVE-2026-9413 [MEDIUM] CWE-79 CVE-2026-9413: A vulnerability was identified in SourceCodester Indian Invoicing System 1.0. The affected element i A vulnerability was identified in SourceCodester Indian Invoicing System 1.0. The affected element is an unknown function of the file /Invoicing/category.php. The manipulation of the argument msg leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and might be used.
cvelistv5nvd
CVE-2026-9414P4LOWCVSS 3.5v0.*v1.02026-05-25
CVE-2026-9414 [LOW] CWE-79 CVE-2026-9414: A security flaw has been discovered in SourceCodester Indian Invoicing System up to 0.x/1.0. The imp A security flaw has been discovered in SourceCodester Indian Invoicing System up to 0.x/1.0. The impacted element is an unknown function of the file /Invoicing/add_order.php of the component Invoice Template Render Database-Backed. The manipulation of the argument customer_name results in cross site scripting. The attack may be launched remotely. The expl
cvelistv5nvd
Sourcecodester Indian Invoicing System vulnerabilities | cvebase