Technology · FOSSBilling
FOSSBilling vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 27 vulnerabilities in FOSSBilling: 0 in the last 7 days and 17 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-53648, was published on 7 July 2026.
- Last 7 days
- 0
- Last 90 days
- 17
- Critical, all time
- 0
- Exploited in the wild
- 0
About FOSSBilling
FOSSBilling is an open-source billing and client management solution designed for service providers.
Latest FOSSBilling vulnerabilities
- CVE-2026-53648: FOSSBilling file overwrite via filename collision in downloadable productsinfoCVSS 5.1
- CVE-2026-53647: FOSSBilling information disclosure in Guest serviceapikey/get_info APIinfoCVSS 6.9
- CVE-2026-53646: FOSSBilling weak password recovery mechanism in Client APIinfoCVSS 7.7
- CVE-2026-53645: FOSSBilling privilege escalation in staff permission managementinfoCVSS 8.5
- CVE-2026-53644: FOSSBilling authorization bypass in Serviceapikey moduleinfoCVSS 8.6
- CVE-2026-53643: FOSSBilling authorization bypass in admin API endpointsinfoCVSS 8.7
- CVE-2026-53642: FOSSBilling incorrect authorization in client area access controlinfoCVSS 5.3
- CVE-2026-53641: FOSSBilling stored XSS in client email history viewsinfoCVSS 4.8
- CVE-2026-53640: FOSSBilling missing authorization in admin API read endpointsinfoCVSS 2.3
- CVE-2026-43928: FOSSBilling invoice underpayment in PayPalEmail adapterinfoCVSS 2.3
- CVE-2026-43927: FOSSBilling race condition in cart checkout promo code validationinfoCVSS 6.9
- CVE-2026-43925: FOSSBilling mass assignment in client self-registrationinfoCVSS 6.9
- CVE-2026-43921: FOSSBilling PHP code injection in Config componentinfoCVSS 8.9
- CVE-2026-43918: FOSSBilling insufficient session expiration for suspended accountsinfoCVSS 8.7
- CVE-2026-42341: FOSSBilling unauthenticated payment bypass in IPN callbackinfoCVSS 9.2
- CVE-2026-42331: FOSSBilling missing authorization in Guest API invoice endpointsinfoCVSS 7.7
- CVE-2026-33734: FOSSBilling SQL injection in Massmailer moduleinfoCVSS 6.9
- CVE-2026-43920: FOSSBilling missing authentication in /run-patcher endpointinfoCVSS 6.9
- CVE-2026-33543: FOSSBilling authentication bypass in guest staff creation APIinfoCVSS 9.3
- CVE-2026-27708: FOSSBilling IDOR in Servicecustom Client APIinfoCVSS 7.1
- CVE-2026-23513: FOSSBilling incorrect authorization in client transaction and order listingsinfoCVSS 7.1
- CVE-2025-64105: FOSSBilling IDOR in support ticket creationinfoCVSS 5.1
- CVE-2026-28496: FOSSBilling Server-Side Template Injection in Twig renderinginfoCVSS 9.4
- CVE-2026-27604: FOSSBilling authorization bypass in system API endpointsinfoCVSS 10
- CVE-2026-43926: FOSSBilling missing rate limiting in password reset and auth endpointsinfoCVSS 6.3
Most severe FOSSBilling vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-27604: FOSSBilling authorization bypass in system API endpointsinfoCVSS 10
- CVE-2026-28496: FOSSBilling Server-Side Template Injection in Twig renderinginfoCVSS 9.4
- CVE-2026-33543: FOSSBilling authentication bypass in guest staff creation APIinfoCVSS 9.3
- CVE-2026-42341: FOSSBilling unauthenticated payment bypass in IPN callbackinfoCVSS 9.2
- CVE-2026-43921: FOSSBilling PHP code injection in Config componentinfoCVSS 8.9
- CVE-2026-53643: FOSSBilling authorization bypass in admin API endpointsinfoCVSS 8.7
- CVE-2026-43918: FOSSBilling insufficient session expiration for suspended accountsinfoCVSS 8.7
- CVE-2026-53644: FOSSBilling authorization bypass in Serviceapikey moduleinfoCVSS 8.6
- CVE-2026-53645: FOSSBilling privilege escalation in staff permission managementinfoCVSS 8.5
- CVE-2026-53646: FOSSBilling weak password recovery mechanism in Client APIinfoCVSS 7.7
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 17 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/fossbilling.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "FOSSBilling vulnerabilities", https://junglewise.ai/threats/technologies/fossbilling, 26 September 2026.