David Bomba
5 exploits
Active since Dec 2021
Invoice Ninja < 5.10.43 - Unauthenticated Remote Code Execution via Route Hash Deserialization
CVSS 8.8
Invoice Ninja Denylist Bypass may Lead to Stored XSS via Invoice Line Items
CVSS 5.4
Invoice Ninja < 4.5.47 and 5.x < 5.3.35 - Stored Cross-Site Scripting
CVSS 5.4
Invoice Ninja 5.8.56-5.11.23 - Authenticated Server-Side Request Forgery
CVSS 7.7
Invoice Ninja <= 5.11.72 - Code Injection