vciy

CVEs we hold for Fossbilling

Records whose assigning authority named Fossbilling as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-53648FOSSBilling: Downloadable product files can be overwritten through filename collisionsFOSSBilling
CVE-2026-53647FOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpointFOSSBilling
CVE-2026-53646FOSSBilling: Client password reset token reuse allows persistent account takeoverFOSSBilling
CVE-2026-53645FOSSBilling's missing self-edit prevention in staff permission management allows persistent privilege escalationFOSSBilling
CVE-2026-53644FOSSBilling's missing order-state validation allows clients to read and reset API key secrets for non-active ordersFOSSBilling
CVE-2026-53643FOSSBilling allows low-privileged staff accounts to perform unauthorized actions via admin API endpointsFOSSBilling
CVE-2026-53642FOSSBilling: Unverified clients can access client-area pages when email confirmation is requiredFOSSBilling
CVE-2026-53641FOSSBilling has stored XSS in client email views via unescaped content in JavaScript template literalFOSSBilling
CVE-2026-53640FOSSBilling missing authorization checks on read-only admin API endpoints expose sensitive staff, client, and redirect…FOSSBilling
CVE-2026-43928FOSSBilling: Payment amount not validated in PayPalEmail adapter allows invoice underpaymentFOSSBilling
CVE-2026-43927FOSSBilling has race condition in cart checkout that bypasses promo code usage limitsFOSSBilling
CVE-2026-43926FOSSBilling's password reset confirmation endpoint lacks rate limitingFOSSBilling
CVE-2026-43925FOSSBilling: Mass assignment of group_id in guest client registration allows unauthorized promo code useFOSSBilling
CVE-2026-43924FOSSBilling has an open redirect via administrator-configured redirect targetsFOSSBilling
CVE-2026-43921FOSSBilling vulnerable to arbitrary PHP code injection via unescaped config serializationFOSSBilling
CVE-2026-43920FOSSBilling: Unauthenticated update patcher endpoint allows remote maintenance executionFOSSBilling
CVE-2026-43918Suspended or inactive FOSSBilling accounts can retain or regain access through existing sessions, API tokens, and…FOSSBilling
CVE-2026-42341FOSSBilling has an unauthenticated payment bypass via IPN callback forgeryFOSSBilling
CVE-2026-42331FOSSBilling missing authorization in guest Invoice API endpointsFOSSBilling
CVE-2026-40495FOSSBilling version exposed via asset cache busterFOSSBilling
CVE-2026-33734FOSSBilling has improper SQL neutralization in `Massmailer` recipient filtersFOSSBilling
CVE-2026-33543FOSSBilling: Authentication bypass allows unauthenticated administrator creationFOSSBilling
CVE-2026-28496FOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCEFOSSBilling
CVE-2026-27708FOSSBilling: IDOR in Servicecustom Client API allows cross-client data accessFOSSBilling
CVE-2026-27604FOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Access to Privileged Admin FunctionsFOSSBilling
CVE-2026-23513FOSSBilling: Broken Authorization in Client Transaction and Order ListingsFOSSBilling
CVE-2025-64105FOSSBilling: IDOR Vulnerability in Support Ticket CreationFOSSBilling
CVE-2023-4005Insufficient Session Expiration in fossbilling/fossbillingfossbilling/fossbilling
CVE-2023-3521Cross-site Scripting (XSS) - Reflected in fossbilling/fossbillingfossbilling/fossbilling
CVE-2023-3493Improper Neutralization of Formula Elements in a CSV File in fossbilling/fossbillingfossbilling/fossbilling
CVE-2023-3491Unrestricted Upload of File with Dangerous Type in fossbilling/fossbillingfossbilling/fossbilling
CVE-2023-3490SQL Injection in fossbilling/fossbillingfossbilling/fossbilling
CVE-2023-3394Session Fixation in fossbilling/fossbillingfossbilling/fossbilling
CVE-2023-3393Code Injection in fossbilling/fossbillingfossbilling/fossbilling
CVE-2023-3230Missing Authorization in fossbilling/fossbillingfossbilling/fossbilling
CVE-2023-3229Business Logic Errors in fossbilling/fossbillingfossbilling/fossbilling
CVE-2023-3228Business Logic Errors in fossbilling/fossbillingfossbilling/fossbilling
CVE-2023-3227Insufficient Granularity of Access Control in fossbilling/fossbillingfossbilling/fossbilling

38 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.