Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows PHP Local File Inclusion.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.9.
Metrics
Affected Vendors & Products
References
History
Tue, 17 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 16 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Boldgrid
Boldgrid client Invoicing By Sprout Invoices Wordpress Wordpress wordpress |
|
| Vendors & Products |
Boldgrid
Boldgrid client Invoicing By Sprout Invoices Wordpress Wordpress wordpress |
Fri, 13 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows PHP Local File Inclusion.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.9. | |
| Title | WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.9 - Local File Inclusion vulnerability | |
| Weaknesses | CWE-98 | |
| References |
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-03-17T13:28:39.690Z
Reserved: 2026-03-12T11:11:14.585Z
Link: CVE-2026-32401
Updated: 2026-03-17T13:24:34.042Z
Status : Awaiting Analysis
Published: 2026-03-13T19:54:56.160
Modified: 2026-03-17T14:16:16.537
Link: CVE-2026-32401
No data.