Description
Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Product notes fields in Invoice Ninja v5.13.0 allow raw HTML via Markdown rendering, enabling stored XSS. The Markdown parser output was not sanitized with `purify::clean()` before being included in invoice templates. This is fixed in v5.13.4 by the vendor by adding `purify::clean()` to sanitize Markdown output.
INFO
Published Date :
2026-03-26T20:50:21.984Z
Last Modified :
2026-03-27T13:55:25.963Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2026-33742 vulnerability.
| Vendors | Products |
|---|---|
| Invoiceninja |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-33742.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact