CVE-2025-67084 - InvoicePlane File Upload RCE
CVE ID : CVE-2025-67084
Published : Jan. 15, 2026, 3:15 p.m. | 42 minutes ago
Description : File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can later be executed remotely, leading to Remote Code Execution (RCE).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Jan. 15, 2026, 3:15 p.m. | 42 minutes ago
Description : File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can later be executed remotely, leading to Remote Code Execution (RCE).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...