← All CVEs

CVE-2025-67084

critical · 9.9

File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can later be executed remotely, leading to Remote Code Execution (RCE).

9.9
CVSS
0.4%
EPSS (exploit prob.)
38th
EPSS percentile
2026-01-15
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-616

Affected products

VendorProductAffected versions
invoiceplaneinvoiceplane< 1.6.4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-67084