CVE-2026-33628 | Invoice Ninja up to 5.13.3 purify::clean Description cross site scripting (GHSA-98wm-cxpw-847p)
A vulnerability marked as problematic has been reported in Invoice Ninja up to 5.13.3. Affected by this vulnerability is the function purify::clean. This manipulation of the argument Description causes cross site scripting.
The identification of this vulnerability is CVE-2026-33628. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.