{"id":"CVE-2026-71233","published":"2026-08-05T11:16:25.997","lastModified":"2026-08-10T12:17:25.770","description":"InvoiceNinja v5-stable renders an invoice or quote's \"terms\" field in the client portal using Laravel Blade's raw output directive {!! ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization.","cvssScore":8.7,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://github.com/invoiceninja/invoiceninja","tags":[]}],"exploitRefs":[{"url":"https://github.com/invoiceninja/invoiceninja","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows an attacker to inject malicious HTML into the client portal by exploiting the raw output directive in the 'terms' field, leading to Cross-Site Scripting (XSS).","exploitability":"Exploitation is relatively easy given the public exploit references and the lack of HTML sanitization. The attacker needs access to the 'terms' field input.","blast_radius":"If exploited, the XSS could lead to session hijacking, data theft, or other client-side attacks affecting all users of the client portal.","remediation":"Upgrade to the latest version of InvoiceNinja v5-stable or apply the vendor's patch immediately.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["xss","html-injection","web","client-portal"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:26:03.207Z"}}