Vulnerabilidades em FOSSBilling

38 resultados
Análise Vexday

FOSSBilling apresenta 27 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando descoberta recente e massiva de falhas. Embora nenhuma esteja sob ataque ativo conhecido, 4 são críticas e a fragilidade dominante (CWE-306: Missing Authentication) aponta para problemas estruturais de controle de acesso que demandam remediação urgente.

CVE-2026-43928LOWFOSSBilling: Payment amount not validated in PayPalEmail adapter allows invoice underpaymentEPSS 0.3%CVE-2026-43921HIGHFOSSBilling vulnerable to arbitrary PHP code injection via unescaped config serializationEPSS 0.3%CVE-2026-27708HIGHFOSSBilling: IDOR in Servicecustom Client API allows cross-client data accessEPSS 0.3%CVE-2025-64105MEDIUMFOSSBilling: IDOR Vulnerability in Support Ticket CreationEPSS 0.3%CVE-2026-53648MEDIUMFOSSBilling: Downloadable product files can be overwritten through filename collisionsEPSS 0.3%CVE-2026-43924MEDIUMFOSSBilling has an open redirect via administrator-configured redirect targetsEPSS 0.3%CVE-2026-53644HIGHFOSSBilling's missing order-state validation allows clients to read and reset API key secrets for non-active ordersEPSS 0.3%CVE-2026-42331HIGHFOSSBilling missing authorization in guest Invoice API endpointsEPSS 0.2%CVE-2026-53645HIGHFOSSBilling's missing self-edit prevention in staff permission management allows persistent privilege escalationEPSS 0.2%CVE-2026-43918HIGHSuspended or inactive FOSSBilling accounts can retain or regain access through existing sessions, API tokens, and password reset flowsEPSS 0.2%CVE-2026-53640LOWFOSSBilling missing authorization checks on read-only admin API endpoints expose sensitive staff, client, and redirect dataEPSS 0.2%CVE-2026-53642MEDIUMFOSSBilling: Unverified clients can access client-area pages when email confirmation is requiredEPSS 0.2%CVE-2026-53643HIGHFOSSBilling allows low-privileged staff accounts to perform unauthorized actions via admin API endpointsEPSS 0.2%CVE-2026-43927MEDIUMFOSSBilling has race condition in cart checkout that bypasses promo code usage limitsEPSS 0.2%CVE-2026-33734MEDIUMFOSSBilling has improper SQL neutralization in `Massmailer` recipient filtersEPSS 0.2%CVE-2026-43926MEDIUMFOSSBilling's password reset confirmation endpoint lacks rate limitingEPSS 0.2%CVE-2026-53646HIGHFOSSBilling: Client password reset token reuse allows persistent account takeoverEPSS 0.2%CVE-2026-42341CRITICALFOSSBilling has an unauthenticated payment bypass via IPN callback forgeryEPSS 0.2%