MEDIUM 6.5 NVD
CVE-2026-61688
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, an authenticated user can view the API request history of any other user's API tokens
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, an authenticated user can view the API request history of any other user's API tokens within the same company by manipulating two writable Symfony UX LiveComponent props on the `DataGrid` component. Version 3.0.1 fixes the issue.
References
- https://github.com/SolidInvoice/SolidInvoice/releases/tag/3.0.1
- https://github.com/SolidInvoice/SolidInvoice/security/advisories/GHSA-jhv9-9fv9-67cr
This medium severity vulnerability with a CVSS score of 6.5 was published on 2026-09-04 via NVD.
vulnfeed aggregates 10236 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.