Niels Drost
12 exploits
Active since Dec 2025
InvoicePlane <=1.6.3 - Path Traversal
CVSS 7.5
InvoicePlane 1.7.0 - Authenticated Stored Cross-Site Scripting via Invoice Logo Upload
CVSS 5.7
InvoicePlane 1.7.0 - Authenticated Stored Cross-Site Scripting via Invoice Number Parameter
CVSS 5.7
InvoicePlane 1.7.0 - Authenticated Stored Cross-Site Scripting via Quote Number Parameter
CVSS 5.7
InvoicePlane 1.7.0 - Authenticated Stored Cross-Site Scripting via SVG Logo Upload
CVSS 5.7
InvoicePlane 1.7.0 - RCE via LFI & Log Poisoning
CVSS 9.1
InvoicePlane < 1.7.1 - Stored Cross-Site Scripting via Family Name Field
CVSS 4.8
InvoicePlane < 1.7.1 - Authenticated Stored Cross-Site Scripting via Invoice Number Field
CVSS 4.8
InvoicePlane < 1.7.1 - Authenticated Stored Cross-Site Scripting via Product Unit Name Field
CVSS 4.8
InvoicePlane - Authenticated Stored Cross-Site Scripting via Invoice Group Identifier Format Field
CVSS 5.4
InvoicePlane - Authenticated Stored Cross-Site Scripting in Sumex Invoice View
CVSS 4.4
InvoicePlane invoices/view - Insecure Direct Object Reference
CVSS 4.3