Vendor
InvoicePlane 1.7.1 is vulnerable to remote code execution (CVE-2026-40297) due to unsanitized input in the setup module, allowing attackers to inject arbitrary configuration directives.