{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-85293","assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","state":"PUBLISHED","assignerShortName":"GitHub_M","dateReserved":"2026-09-03T16:37:49.262Z","datePublished":"2026-09-25T15:29:30.089Z","dateUpdated":"2026-09-25T15:59:04.796Z"},"containers":{"cna":{"title":"InvoicePlane: Stored Cross-Site Scripting (XSS) via Client Email in Invoice and Quote Mailer Forms","problemTypes":[{"descriptions":[{"cweId":"CWE-79","lang":"en","description":"CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-87","lang":"en","description":"CWE-87: Improper Neutralization of Alternate XSS Syntax","type":"CWE"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","version":"3.1"}}],"references":[{"name":"https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-477r-xmgc-vcvj","tags":["x_refsource_CONFIRM"],"url":"https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-477r-xmgc-vcvj"},{"name":"https://github.com/InvoicePlane/InvoicePlane/pull/1635","tags":["x_refsource_MISC"],"url":"https://github.com/InvoicePlane/InvoicePlane/pull/1635"},{"name":"https://github.com/InvoicePlane/InvoicePlane/commit/1e74c032ff1c65e6a4f9d173505f415c3a539f57","tags":["x_refsource_MISC"],"url":"https://github.com/InvoicePlane/InvoicePlane/commit/1e74c032ff1c65e6a4f9d173505f415c3a539f57"},{"name":"https://github.com/InvoicePlane/InvoicePlane/releases/tag/v1.7.2","tags":["x_refsource_MISC"],"url":"https://github.com/InvoicePlane/InvoicePlane/releases/tag/v1.7.2"}],"affected":[{"vendor":"InvoicePlane","product":"InvoicePlane","versions":[{"version":"< 1.7.2","status":"affected"}]}],"providerMetadata":{"orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M","dateUpdated":"2026-09-25T15:29:30.089Z"},"descriptions":[{"lang":"en","value":"InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2-beta-1, InvoicePlane stores client_email values without enforcing email syntax and renders them unescaped inside double-quoted value attributes in the invoice mailer form and quote mailer form. An administrator who can edit a client can store attribute-breaking input, and, when the mailer is configured, JavaScript executes when another authenticated administrator opens the related mailer page. The script runs in the InvoicePlane origin and can perform same-origin actions with the victim's session. This issue is fixed in version 1.7.2."}],"source":{"advisory":"GHSA-477r-xmgc-vcvj","discovery":"UNKNOWN"}},"adp":[{"references":[{"url":"https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-477r-xmgc-vcvj","tags":["exploit"]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-25T15:58:37.209317Z","id":"CVE-2026-85293","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-25T15:59:04.796Z"}}]}}