CVE-2025-67083

MEDIUM

InvoicePlane <= 1.6.3 - Unauthenticated Directory Traversal

Title source: llm
STIX 2.1

Description

Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the server. The ability to read files and the file type depends on the web server and its configuration.

References (2)

Core 2

Scores

CVSS v3 5.3
EPSS 0.0061
EPSS Percentile 44.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
invoiceplane/invoiceplane < 1.6.4
Published Jan 15, 2026
Tracked Since Feb 18, 2026