CVE-2026-61614
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the REST API authenticator accepts bearer tokens via a `?token=` URL query parameter as a fallback to the `X-API-TOKEN` header. This causes long-lived API credentials to be recorded in server access logs, proxy logs, browser history, and HTTP Referer headers sent to third-party origins. Version 3.0.1 fixes the issue.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.9
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.28%
- CWE
- CWE-598
- Published
- 2026-09-04
- Last modified
- 2026-09-04
Affected products
- SolidInvoice SolidInvoice
Weakness type
Related vulnerabilities
- CVE-2026-88897 — Flextype CMS through 1.0.0-alpha.3 API Token Exposure via Query String
- CVE-2026-82181 — Le-yan|Medical Practice Management System - Sensitive Data in URL
- CVE-2026-76179 — Ebyte NA111-M Use of GET Request Method With Sensitive Query Strings
- CVE-2026-63408 — Grav API Plugin: JWT Access Token Accepted via `?token=` URL Query Parameter
- CVE-2026-74880 — openssl_encrypt before 1.4.0 Token Leakage via Query Parameters
- CVE-2026-66832 — Mira Hormone Monitor, Mira Android App Use of GET request method with sensitive query strings
- CVE-2026-14838 — Session Token Exposure in URL Leading to Account Takeover in Bilin Software's HUMANIST Digital Human Resources
- CVE-2026-47768 — nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)