Vulnerabilidades em FOSSBilling
38 resultadosAnálise Vexday
FOSSBilling apresenta 27 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando descoberta recente e massiva de falhas. Embora nenhuma esteja sob ataque ativo conhecido, 4 são críticas e a fragilidade dominante (CWE-306: Missing Authentication) aponta para problemas estruturais de controle de acesso que demandam remediação urgente.
CVE-2026-28496CRITICALFOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCEEPSS 1.9%CVE-2023-3393HIGHCode Injection in fossbilling/fossbillingEPSS 1.0%CVE-2023-3490CRITICALSQL Injection in fossbilling/fossbillingEPSS 0.9%CVE-2023-3521MEDIUMCross-site Scripting (XSS) - Reflected in fossbilling/fossbillingEPSS 0.9%CVE-2026-43920MEDIUMFOSSBilling: Unauthenticated update patcher endpoint allows remote maintenance executionEPSS 0.9%CVE-2023-3491HIGHUnrestricted Upload of File with Dangerous Type in fossbilling/fossbillingEPSS 0.9%CVE-2026-53647MEDIUMFOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpointEPSS 0.5%CVE-2023-3493HIGHImproper Neutralization of Formula Elements in a CSV File in fossbilling/fossbillingEPSS 0.5%CVE-2026-27604CRITICALFOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Access to Privileged Admin FunctionsEPSS 0.5%CVE-2023-3229MEDIUMBusiness Logic Errors in fossbilling/fossbillingEPSS 0.5%CVE-2023-3394MEDIUMSession Fixation in fossbilling/fossbillingEPSS 0.5%CVE-2023-4005LOWInsufficient Session Expiration in fossbilling/fossbillingEPSS 0.5%CVE-2023-3228MEDIUMBusiness Logic Errors in fossbilling/fossbillingEPSS 0.5%CVE-2026-43925MEDIUMFOSSBilling: Mass assignment of group_id in guest client registration allows unauthorized promo code useEPSS 0.5%CVE-2026-33543CRITICALFOSSBilling: Authentication bypass allows unauthenticated administrator creationEPSS 0.4%CVE-2026-53641MEDIUMFOSSBilling has stored XSS in client email views via unescaped content in JavaScript template literalEPSS 0.4%CVE-2026-43921HIGHFOSSBilling vulnerable to arbitrary PHP code injection via unescaped config serializationEPSS 0.4%CVE-2026-43928LOWFOSSBilling: Payment amount not validated in PayPalEmail adapter allows invoice underpaymentEPSS 0.4%CVE-2026-42331HIGHFOSSBilling missing authorization in guest Invoice API endpointsEPSS 0.4%CVE-2026-53648MEDIUMFOSSBilling: Downloadable product files can be overwritten through filename collisionsEPSS 0.4%