Skip to content

Release history

InvoicePlane releases

A self-hosted open source application for managing your invoices, clients and payments.

All releases

4 shown

v1.6.5 Security relevant
Breaking changes
  • SVG logo uploads now disabled
Security fixes
  • XSS vulnerabilities fixed through sanitization
  • SVG upload restriction to prevent XSS
v1.7.1 Security relevant
Breaking changes
  • SVG logo uploads now disabled; existing SVGs blocked
Security fixes
  • Multiple XSS vulnerabilities fixed through input sanitization and output escaping
  • SVG logo XSS vectors eliminated by disabling SVG uploads
Notable features
  • Proper HTML escaping of invoice numbers, tax rates, and payment methods
  • SVG upload restriction to PNG/JPG/GIF only
v1.6.4 Security relevant
Security fixes
  • File access vulnerabilities across all controllers
  • Log sanitization for client einvoicing fields
Notable features
  • PayPal Advanced Credit Cards & Venmo support
  • Email address verification with comma/semicolon support

Beta — feedback welcome: [email protected]