Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows PHP Local File Inclusion.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.9.
We have discovered 368 live websites that are affected by CVE-2026-32401.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 368 live websites (86% of Sprout Invoices install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 41 versions ( 95% of all versions) |
| 215 websites | |
| 36 websites | |
| 19 websites | |
| 13 websites | |
| 8 websites | |
| 8 websites | |
| 8 websites | |
| 8 websites | |
| 5 websites | |
| .com | 247 websites |
| .co.uk | 14 websites |
| .net | 13 websites |
| .fr | 7 websites |
| .ca | 7 websites |
| .com.au | 6 websites |
| .org | 6 websites |
| .ch | 4 websites |
| .se | 2 websites |
| .cz | 2 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.com | *,*** | ||
| *******.****.es | **,*** | ||
| ************.com | ***,*** | ||
| ******************.com | ***,*** | ||
| *******.com | ***,*** | ||
| **********.com | ***,*** | ||
| *******************.com | ***,*** | ||
| ******.eu | ***,*** | ||
| *************.com | ***,*** | ||
| ******.io | ***,*** |
FAQ