Ad

CVE-2026-34366

HIGH CVSS 3.1: 8.1 EPSS 0.03%
Updated Apr 07, 2026
Invoiceshelf
Parameter Value
CVSS 8.1 (HIGH)
Affected Versions before 2.2.0
Fixed In 2.2.0
Type CWE-918 (Server-Side Request Forgery (SSRF))
Vendor Invoiceshelf
Public PoC No

InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.2.0, a Server-Side Request Forgery (SSRF) vulnerability exists in the Payment receipt PDF generation module. User-supplied HTML in the payment Notes field is passed unsanitised to the Dompdf rendering library, which will fetch any remote resources referenced in the markup.

The vulnerability is exploitable directly via the PDF receipt endpoint, regardless of whether automated email attachments are enabled. This issue has been patched in version 2.2.0.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Invoiceshelf Invoiceshelf
cpe:2.3:a:invoiceshelf:invoiceshelf:*:*:*:*:*:*:*:*
2.2.0