Threat Intel

v0.1

← CVEs

CVE-2025-67084

CRIT 9.9
Published
2026-01-15
Last Modified
2026-01-22
Affected Apps
1
Affected Devices
1
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can later be executed remotely, leading to Remote Code Execution (RCE).
Affected Applications in Environment 1
Plane v1.0
1 device
Affected Devices 1
DPAVTE-DH77B74 Windows
References 2