{"api_version":"v1","generated_at":"2026-10-10T01:30:00+00:00","product":{"cve_count":9,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-boldgrid-client-invoicing-by-sprout-invoices-58083052a5dc","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Client Invoicing by Sprout Invoices","next_cursor":null,"observations":[{"affected":"Client Invoicing by Sprout Invoices: n/a \u2264 20.8.17","affected_versions_present":true,"cve_id":"CVE-2026-97078","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-97078","fixed":"Update the WordPress Client Invoicing by Sprout Invoices plugin to the latest available version (at least 20.8.18).","last_modified":"2026-09-30T13:27:07.807Z","patch_url":"https://patchstack.com/database/wordpress/plugin/sprout-invoices/vulnerability/wordpress-client-invoicing-by-sprout-invoices-plugin-20-8-17-insecure-direct-object-references-idor-vulnerability?_s_id=cve","primary_source":"","published":"2026-09-30T12:27:53.286Z"},{"affected":"\u2264 20.8.13","affected_versions_present":true,"cve_id":"CVE-2026-57418","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-57418","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-13T13:34:37.297Z","patch_url":"","primary_source":"","published":"2026-07-13T08:41:24.384Z"},{"affected":"\u2264 20.8.10","affected_versions_present":true,"cve_id":"CVE-2026-39562","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-39562","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-29T09:52:02.114Z","patch_url":"","primary_source":"","published":"2026-04-08T08:30:18.463Z"},{"affected":"\u2264 20.8.9","affected_versions_present":true,"cve_id":"CVE-2026-32401","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-32401","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-29T09:51:58.783Z","patch_url":"","primary_source":"","published":"2026-03-13T11:42:12.509Z"},{"affected":"\u2264 20.8.8","affected_versions_present":true,"cve_id":"CVE-2026-25364","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25364","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-28T16:14:56.851Z","patch_url":"","primary_source":"","published":"2026-02-19T08:26:59.312Z"},{"affected":"Client Invoicing by Sprout Invoices: \u2264 20.8.7","affected_versions_present":true,"cve_id":"CVE-2025-64227","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-64227","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-28T18:26:32.070Z","patch_url":"","primary_source":"","published":"2025-12-18T07:22:13.423Z"},{"affected":"\u2264 20.8.7","affected_versions_present":true,"cve_id":"CVE-2025-64229","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-64229","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-28T18:26:50.524Z","patch_url":"","primary_source":"","published":"2025-10-29T08:38:11.498Z"},{"affected":"\u2264 20.8.1","affected_versions_present":true,"cve_id":"CVE-2025-24606","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-24606","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-29T09:51:54.235Z","patch_url":"","primary_source":"","published":"2025-01-27T14:22:16.064Z"},{"affected":"\u2264 20.8.0","affected_versions_present":true,"cve_id":"CVE-2024-53819","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-53819","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-28T16:10:46.900Z","patch_url":"","primary_source":"","published":"2024-12-09T12:26:56.848Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"BoldGrid"}}
