Skip to content
InvoicePlane
Productivity & Wikis
A self-hosted open source application for managing your invoices, clients and payments.
PHP
·
Latest v1.6.5 · 3mo ago
Security brief →
Features
-
Manage invoices and quotes effortlessly
-
Track clients and their transaction history
-
Monitor payments and generate financial reports
v1.6.5
Security relevant
·
Breaking changes
- SVG logo uploads now disabled
Security fixes
- XSS vulnerabilities fixed through sanitization
- SVG upload restriction to prevent XSS
v1.7.1
Security relevant
·
Breaking changes
- SVG logo uploads now disabled; existing SVGs blocked
Security fixes
- Multiple XSS vulnerabilities fixed through input sanitization and output escaping
- SVG logo XSS vectors eliminated by disabling SVG uploads
Notable features
- Proper HTML escaping of invoice numbers, tax rates, and payment methods
- SVG upload restriction to PNG/JPG/GIF only
v1.6.4
Security relevant
·
Security fixes
- File access vulnerabilities across all controllers
- Log sanitization for client einvoicing fields
Notable features
- PayPal Advanced Credit Cards & Venmo support
- Email address verification with comma/semicolon support
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
About
Languages
PHP
·
SCSS
·
JavaScript
View on GitHub
Homepage
Search tools, categories, lists, and users
Use ↑↓ to navigate, Enter to open, Esc to close
No results for ""
⌘K to open
↑↓ navigate
⏎ open