CVE-2025-67084CRITICAL 9.9EPSS p31.7%
CVE-2025-67084CVE-2025-67084
Description
File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can later be executed remotely, leading to Remote Code Execution (RCE).
Scoring
| CVSS 3.1 | 9.9 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 0.40% probability of exploitation · percentile 31.7% · 2026-06-18T12:00:27Z |
| Published | 2026-01-15 |
| Last modified | 2026-01-22 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Incomplete Identification of Uploaded File Variables (PHP)cwe-616 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.