
🚨 CVE-2026-23491 - high 🚨 InvoicePlane <= 1.6.3 - Arbitrary File Read > InvoicePlane through 1.6.3 is vulnerable to an unauthenticated path traversal in the ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-23491 @pdnuclei #NucleiTemplates #cve
Post summary
The tweet announces an unauthenticated path traversal in InvoicePlane versions up to 1.6.3, includes a link to a projectdiscovery library (likely a PoC), but does not mention active exploitation, patches, or detailed exploit code.

