CVE-2026-34367
InvoiceShelf: SSRF in Invoice PDF Rendering via Unsanitised HTML in Notes Field
CVSS Score
7.6
EPSS Score
0.0%
EPSS Percentile
7th
InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.2.0, a Server-Side Request Forgery (SSRF) vulnerability exists in the Invoice PDF generation module. User-supplied HTML in the invoice Notes field is passed unsanitised to the Dompdf rendering library, which will fetch any remote resources referenced in the markup. This can be triggered via the PDF preview and email delivery endpoints. This issue has been patched in version 2.2.0.
| CWE | CWE-918 |
| Vendor | invoiceshelf |
| Product | invoiceshelf |
| Published | Mar 31, 2026 |
| Last Updated | Apr 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for invoiceshelf invoiceshelf
Be the first to know when new high vulnerabilities affecting invoiceshelf invoiceshelf are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None
Affected Versions
InvoiceShelf / InvoiceShelf
< 2.2.0