CVE-2026-34365 | InvoiceShelf up to 2.1.x Estimate PDF Generation Estimate Notes server-side request forgery (GHSA-pc5v-8xwc-v9xq)
A vulnerability classified as critical has been found in InvoiceShelf up to 2.1.x. Affected is an unknown function of the component Estimate PDF Generation Module. Performing a manipulation of the argument Estimate Notes results in server-side request forgery.
This vulnerability is reported as CVE-2026-34365. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.