๐Ÿ” CVE Alert

CVE-2026-9414

LOW 3.5

SourceCodester Indian Invoicing System Invoice Template Render Database-Backed add_order.php cross site scripting

CVSS Score
3.5
EPSS Score
0.0%
EPSS Percentile
9th

A security flaw has been discovered in SourceCodester Indian Invoicing System up to 0.x/1.0. The impacted element is an unknown function of the file /Invoicing/add_order.php of the component Invoice Template Render Database-Backed. The manipulation of the argument customer_name results in cross site scripting. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

CWE CWE-79 CWE-94
Vendor sourcecodester
Product indian invoicing system
Published May 25, 2026
Last Updated May 26, 2026
Stay Ahead of the Next One

Get instant alerts for sourcecodester indian invoicing system

Be the first to know when new low vulnerabilities affecting sourcecodester indian invoicing system are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

SourceCodester / Indian Invoicing System
0.* 1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/365395 vuldb.com: https://vuldb.com/vuln/365395/cti vuldb.com: https://vuldb.com/submit/813610 gist.github.com: https://gist.github.com/c4ttr4ck/97c5babe1f16fa3243333528a40b7550 sourcecodester.com: https://www.sourcecodester.com/

Credits

๐Ÿ” c4ttr4ck (VulDB User)