FOSSBilling / FOSSBilling
27 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-53648 | FOSSBilling: Downloadable product files can be overwritten through filename collisions | MEDIUM | 5.1 | Jul 6, 2026 |
| CVE-2026-53647 | FOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpoint | MEDIUM | 6.9 | Jul 6, 2026 |
| CVE-2026-53646 | FOSSBilling: Client password reset token reuse allows persistent account takeover | HIGH | 7.7 | Jul 6, 2026 |
| CVE-2026-53645 | FOSSBilling's missing self-edit prevention in staff permission management allows persistent privilege escalation | HIGH | 8.5 | Jul 6, 2026 |
| CVE-2026-53644 | FOSSBilling's missing order-state validation allows clients to read and reset API key secrets for non-active orders | HIGH | 8.6 | Jul 6, 2026 |
| CVE-2026-53643 | FOSSBilling allows low-privileged staff accounts to perform unauthorized actions via admin API endpoints | HIGH | 8.7 | Jul 6, 2026 |
| CVE-2026-53642 | FOSSBilling: Unverified clients can access client-area pages when email confirmation is required | MEDIUM | 5.3 | Jul 6, 2026 |
| CVE-2026-53641 | FOSSBilling has stored XSS in client email views via unescaped content in JavaScript template literal | MEDIUM | 4.8 | Jul 6, 2026 |
| CVE-2026-53640 | FOSSBilling missing authorization checks on read-only admin API endpoints expose sensitive staff, client, and redirect data | LOW | 2.3 | Jul 6, 2026 |
| CVE-2026-43928 | FOSSBilling: Payment amount not validated in PayPalEmail adapter allows invoice underpayment | LOW | 2.3 | Jul 6, 2026 |
| CVE-2026-43927 | FOSSBilling has race condition in cart checkout that bypasses promo code usage limits | MEDIUM | 6.9 | Jul 6, 2026 |
| CVE-2026-43925 | FOSSBilling: Mass assignment of group_id in guest client registration allows unauthorized promo code use | MEDIUM | 6.9 | Jul 6, 2026 |
| CVE-2026-43921 | FOSSBilling vulnerable to arbitrary PHP code injection via unescaped config serialization | HIGH | 8.9 | Jul 6, 2026 |
| CVE-2026-43918 | Suspended or inactive FOSSBilling accounts can retain or regain access through existing sessions, API tokens, and password reset flows | HIGH | 8.7 | Jul 6, 2026 |
| CVE-2026-42331 | FOSSBilling missing authorization in guest Invoice API endpoints | HIGH | 7.7 | Jul 6, 2026 |
| CVE-2026-33734 | FOSSBilling has improper SQL neutralization in `Massmailer` recipient filters | MEDIUM | 6.9 | Jul 6, 2026 |
| CVE-2026-42341 | FOSSBilling has an unauthenticated payment bypass via IPN callback forgery | CRITICAL | 9.2 | Jul 6, 2026 |
| CVE-2026-43920 | FOSSBilling: Unauthenticated update patcher endpoint allows remote maintenance execution | MEDIUM | 6.9 | Jun 25, 2026 |
| CVE-2026-33543 | FOSSBilling: Authentication bypass allows unauthenticated administrator creation | CRITICAL | 9.3 | Jun 24, 2026 |
| CVE-2026-27708 | FOSSBilling: IDOR in Servicecustom Client API allows cross-client data access | HIGH | 7.1 | Jun 24, 2026 |
| CVE-2026-23513 | FOSSBilling: Broken Authorization in Client Transaction and Order Listings | HIGH | 7.1 | Jun 23, 2026 |
| CVE-2025-64105 | FOSSBilling: IDOR Vulnerability in Support Ticket Creation | MEDIUM | 5.1 | Jun 23, 2026 |
| CVE-2026-27604 | FOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Access to Privileged Admin Functions | CRITICAL | 10.0 | Jun 23, 2026 |
| CVE-2026-28496 | FOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCE | CRITICAL | 9.4 | Jun 23, 2026 |
| CVE-2026-43926 | FOSSBilling's password reset confirmation endpoint lacks rate limiting | MEDIUM | 6.3 | Jun 4, 2026 |
Showing 1 to 25 of 27 CVEs