Fossbilling
36 CVEs tracked since 2023. Since Jun 2023, none of them reached CISA KEV.
Fossbilling CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2023-06 | 9 | 0 |
| 2023-07 | null or fewer | |
| 2023-08 | null or fewer | |
| 2023-09 | null or fewer | |
| 2023-10 | null or fewer | |
| 2023-11 | null or fewer | |
| 2023-12 | null or fewer | |
| 2024-01 | null or fewer | |
| 2024-02 | null or fewer | |
| 2024-03 | null or fewer | |
| 2024-04 | null or fewer | |
| 2024-05 | null or fewer | |
| 2024-06 | null or fewer | |
| 2024-07 | null or fewer | |
| 2024-08 | null or fewer | |
| 2024-09 | null or fewer | |
| 2024-10 | null or fewer | |
| 2024-11 | null or fewer | |
| 2024-12 | null or fewer | |
| 2025-01 | null or fewer | |
| 2025-02 | null or fewer | |
| 2025-03 | null or fewer | |
| 2025-04 | null or fewer | |
| 2025-05 | null or fewer | |
| 2025-06 | null or fewer | |
| 2025-07 | null or fewer | |
| 2025-08 | null or fewer | |
| 2025-09 | null or fewer | |
| 2025-10 | null or fewer | |
| 2025-11 | null or fewer | |
| 2025-12 | null or fewer | |
| 2026-01 | null or fewer | |
| 2026-02 | null or fewer | |
| 2026-03 | null or fewer | |
| 2026-04 | null or fewer | |
| 2026-05 | null or fewer | |
| 2026-06 | 10 | 0 |
| 2026-07 | 17 | 0 |
Products
The products that kept showing up in Fossbilling's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Fossbilling.
- CVE-2026-53648FOSSBilling: Downloadable product files can be overwritten through filename collisions—
- CVE-2026-53647FOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpoint—
- CVE-2026-53646FOSSBilling: Client password reset token reuse allows persistent account takeover—
- CVE-2026-53645FOSSBilling's missing self-edit prevention in staff permission management allows persistent privilege escalation—
- CVE-2026-53644FOSSBilling's missing order-state validation allows clients to read and reset API key secrets for non-active orders—
- CVE-2026-53643FOSSBilling allows low-privileged staff accounts to perform unauthorized actions via admin API endpoints—
- CVE-2026-53642FOSSBilling: Unverified clients can access client-area pages when email confirmation is required—
- CVE-2026-53641FOSSBilling has stored XSS in client email views via unescaped content in JavaScript template literal—
- CVE-2026-53640FOSSBilling missing authorization checks on read-only admin API endpoints expose sensitive staff, client, and redirect data—
- CVE-2026-43928FOSSBilling: Payment amount not validated in PayPalEmail adapter allows invoice underpayment—
- CVE-2026-43927FOSSBilling has race condition in cart checkout that bypasses promo code usage limits—
- CVE-2026-43925FOSSBilling: Mass assignment of group_id in guest client registration allows unauthorized promo code use—
- CVE-2026-43921FOSSBilling vulnerable to arbitrary PHP code injection via unescaped config serialization—
- CVE-2026-43918Suspended or inactive FOSSBilling accounts can retain or regain access through existing sessions, API tokens, and password reset flows—
- CVE-2026-42331FOSSBilling missing authorization in guest Invoice API endpoints—
The record
- Peak rank
- #74 in Jun 2023
- Busiest month shown
- Jul 2026, 17 CVEs
- Months with a KEV entry
- 0 since Jun 2023
- Monthly snapshots
- 3 since 2023