Invoice Ninja versions up to 5.11.72 are affected by an authenticated remote code execution vulnerability in the admin 'Restore' function. Attackers with admin credentials can upload malicious .php files, leading to arbitrary code execution on the server. The issue is resolved in version 5.11.73.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
High-severity CVE entries were published for several WordPress components: WorkScout-Core Plugin before 1.7.06, Custom Post Type Images Plugin 0.5 and earlier, Constructo Theme 4.3.9 and earlier, Findgo Theme 1.3.55 and earlier, and CouponXxL Theme 4.5.0 and earlier. All were described as cross-site request forgery vulnerabilities.
A high-severity vulnerability entry was published for CVE-2025-10009, described as an authenticated admin remote code execution issue in Invoice Ninja.
A pull request was published to the ProjectDiscovery nuclei-templates repository adding detection coverage for CVE-2020-36731, marked as vKEV.
7 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.