CVE-2026-24913

SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be obtained or altered by a user who can log in to the product.
References
Link Resource
https://jvn.jp/en/jp/JVN33581068/ Third Party Advisory
https://oss.icz.co.jp/news/?p=1386 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:icz:matcha_invoice:*:*:*:*:*:*:*:*

History

17 Apr 2026, 20:44

Type Values Removed Values Added
CPE cpe:2.3:a:icz:matcha_invoice:*:*:*:*:*:*:*:*
References () https://jvn.jp/en/jp/JVN33581068/ - () https://jvn.jp/en/jp/JVN33581068/ - Third Party Advisory
References () https://oss.icz.co.jp/news/?p=1386 - () https://oss.icz.co.jp/news/?p=1386 - Vendor Advisory
First Time Icz
Icz matcha Invoice

08 Apr 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-08 06:16

Updated : 2026-04-17 20:44


NVD link : CVE-2026-24913

Mitre link : CVE-2026-24913

CVE.ORG link : CVE-2026-24913


JSON object : View

Products Affected

icz

  • matcha_invoice
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')