OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-33639

HIGH · CVSS 7.2 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

InvoicePlane versions prior to 1.7.2 are vulnerable due to improper validation of the administrator-controlled tax_rate_decimal_places setting, allowing attackers to inject malicious SQL clauses into an ALTER TABLE statement. This can lead to schema corruption, potentially altering or removing critical database columns and rendering the application inoperable. Organizations using InvoicePlane should prioritize upgrading to version 1.7.2 to mitigate the risk of financial data loss and application downtime.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-33639
Severity
HIGH
CVSS
7.2
EPSS
0.40%

Original NVD Description

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane interpolates the administrator-controlled tax_rate_decimal_places setting into an ALTER TABLE statement for ip_tax_rates in Settings::index() without strict integer validation. A crafted setting value can add clauses to the schema-changing statement and remove or alter required database columns. The resulting schema corruption can permanently modify financial data structures and make the application unavailable. This vulnerability is fixed in 1.7.2.