
CVE-2026-26281 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A stored cross-site scripting (XSS) vulnerability in the Sumex inv… https://www.cve.org/CVERecord?id=CVE-2026-26281
Post summary
The CVE-2026-26281 is a stored XSS vulnerability in InvoicePlane's Sumex module, with no mention of PoC, exploitation, or patch.

