CyberRota Analysis
AI-GeneratedInvoice Ninja v5.13.24 contains a vulnerability that enables remote attackers to access sensitive information through the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components. Organizations using this version of Invoice Ninja should prioritize patching to mitigate the risk of data exposure. Immediate action is recommended for those handling sensitive financial or personal data.
CVE
CVE-2026-71626
Severity
HIGH
CVSS
7.5
EPSS
0.32%
Original NVD Description
An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components