CVE-2026-24913Disclosure(icz / matcha_invoice)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch icz matcha_invoice systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be obtained or altered by a user who can log in to the product.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • matcha_invoice

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-08); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
matcha_invoice

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-08: 3Mentions · 2026-04-13: 1Patch / Workaround · 2026-04-08: 1Technical Details · 2026-04-08: 3Technical Details · 2026-04-13: 104-0804-13
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-083
Disclosure2Patch1
2026-04-131
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-24913 SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be obtained or alte… https://www.cve.org/CVERecord?id=CVE-2026-24913

    Post summary

    A SQL injection vulnerability (CVE-2026-24913) affecting MATCHA INVOICE 2.6.6 and earlier is disclosed, indicating that database information could be retrieved if exploited.

    00000133
    57.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24913 SQL Injection Vulnerability in MATCHA INVOICE 2.6.6 and Earlier Versions https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24913

    Post summary

    A SQL injection vulnerability (CVE-2026-24913) has been identified in MATCHA INVOICE 2.6.6 and earlier, with no corroborating exploitation or patch details provided.

    0000051
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-24913: HIGH] Beware! SQL Injection vulnerability in MATCHA INVOICE 2.6.6 allows unauthorized users to access or modify database info. Update now to stay secure. #cybersecurity#cve,CVE-2026-24913,#cybersecurity https://cvefind.com/CVE-2026-24913

    Post summary

    The tweet alerts users to a SQL injection vulnerability in MATCHA INVOICE 2.6.6 and urges them to apply a patch while briefly describing the flaw.

    0000042
    619 followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** Multiple vulnerabilities in 抹茶シリーズ (SQL Injection, XSS, Insecure File Upload) 📅 **Timeline:** Disclosure: Not Available, Patch: Not Available 🆔 **CVE-2026-24913** | 📊 CVSS: 8.8 (High 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-27787** | 📊 CVSS: 8.8 (High 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-33273** | 📊 CVSS: 8.8 (High 🟠) | 📈 EPSS: Not Available% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** 抹茶請求書 2.6.6 およびそれ以前, 抹茶SNS 1.3.9 およびそれ以前 🫨 **Attack Vectors:** - SQL Injection (authenticated) - Stored Cross-Site Scripting (XSS) - Insecure file upload allowing arbitrary file creation leading to potential code execution 📝 **Summary:** Multiple high-severity vulnerabilities in the 抹茶シリーズ allow authenticated SQL injection, stored XSS, and insecure file uploads that can lead to database compromise, session theft/phishing, and server-side arbitrary file creation with potential RCE. No vendor patches are available yet, so immediate mitigation, monitoring, and preparation for patch deployment are required. 📈 **Impact Scope:** Potential unauthorized database access/modification, script execution in site visitors' browsers (session/cookie theft, phishing), and arbitrary file creation on server possibly leading to remote code execution and full server compromise. 🛡️ **Recommended Actions:** - Apply vendor-supplied fixes/updates as soon as available - Harden authentication and enforce least privilege for admin accounts - Validate/sanitize inputs and use parameterized queries; encode outputs to mitigate XSS - Enforce strict file upload validation, scan content, and store uploads outside the web root - Deploy or tune WAF rules and increase log monitoring for IOCs - Rotate credentials and ensure recent backups & an incident response plan 🪢 **Related Resources:** - https://jvn.jp/jp/JVN33581068/ - https://jvndb.jvn.jp/jvndb/JVNDB-2026-000052 🏷 **Tags:** #Cybersecurity #WebApp #SQLi_XSS

    Post summary

    The post announces three high‑severity CVEs in the 抹茶シリーズ software, describing SQL injection, XSS, and insecure file upload vulnerabilities, with no patches yet but recommended mitigation steps.

    0000041
    276 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appiczmatcha_invoice---

Explore more