SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-65516

HIGH · CVSS 7.2 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

PeproDev Ultimate Invoice versions up to 2.2.6 are susceptible to an unauthenticated Server Side Request Forgery (SSRF) vulnerability, allowing attackers to send crafted requests from the server to internal or external resources. This could lead to unauthorized access to sensitive data or services, potentially compromising the integrity of the affected systems. Organizations using this software should prioritize patching or mitigating this vulnerability to protect against potential exploitation.

CVE
CVE-2026-65516
Severity
HIGH
CVSS
7.2
EPSS
0.19%

Original NVD Description

Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.