CVE Tools

Fossbilling

36 CVEs tracked since 2023. Since Jun 2023, none of them reached CISA KEV.

Fossbilling CVEs per month

Jun 2023 to Jul 2026. Point at a month, or focus the strip and use the arrow keys.
Fossbilling CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2023-0690
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-04null or fewer
2026-05null or fewer
2026-06100
2026-07170

Products

The products that kept showing up in Fossbilling's monthly top three, with their CVEs summed over those months.

  1. Fossbilling363 months
  2. Fossbilling/fossbilling91 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Fossbilling.

  1. CVE-2026-53648FOSSBilling: Downloadable product files can be overwritten through filename collisions—
  2. CVE-2026-53647FOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpoint—
  3. CVE-2026-53646FOSSBilling: Client password reset token reuse allows persistent account takeover—
  4. CVE-2026-53645FOSSBilling's missing self-edit prevention in staff permission management allows persistent privilege escalation—
  5. CVE-2026-53644FOSSBilling's missing order-state validation allows clients to read and reset API key secrets for non-active orders—
  6. CVE-2026-53643FOSSBilling allows low-privileged staff accounts to perform unauthorized actions via admin API endpoints—
  7. CVE-2026-53642FOSSBilling: Unverified clients can access client-area pages when email confirmation is required—
  8. CVE-2026-53641FOSSBilling has stored XSS in client email views via unescaped content in JavaScript template literal—
  9. CVE-2026-53640FOSSBilling missing authorization checks on read-only admin API endpoints expose sensitive staff, client, and redirect data—
  10. CVE-2026-43928FOSSBilling: Payment amount not validated in PayPalEmail adapter allows invoice underpayment—
  11. CVE-2026-43927FOSSBilling has race condition in cart checkout that bypasses promo code usage limits—
  12. CVE-2026-43925FOSSBilling: Mass assignment of group_id in guest client registration allows unauthorized promo code use—
  13. CVE-2026-43921FOSSBilling vulnerable to arbitrary PHP code injection via unescaped config serialization—
  14. CVE-2026-43918Suspended or inactive FOSSBilling accounts can retain or regain access through existing sessions, API tokens, and password reset flows—
  15. CVE-2026-42331FOSSBilling missing authorization in guest Invoice API endpoints—

The record

Peak rank
#74 in Jun 2023
Busiest month shown
Jul 2026, 17 CVEs
Months with a KEV entry
0 since Jun 2023
Monthly snapshots
3 since 2023
Fossbilling's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store