File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments,…
mitre·CWE-616·Published 2026-01-15