Report: CVE-2026-33273 - Matcha Invoice File Upload Code Execution Vulnerability

Report: CVE-2026-33273 - Matcha Invoice File Upload Code Execution Vulnerability

CVE ID :CVE-2026-33273 Published : April 8, 2026, 5:11 a.m. | 56 minutes ago Description :Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, an arbitrary file may be created by an administrator of the product. As a result, arbitrary code may be executed on the server. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
April 8, 2026