Please note that both VAT Number fields are unsanitized leading to possible XSS exploits, as you can see in the attached screenshot.
The VAT fields should allow only letters, numbers, / and .
Also there's the following notice:
PHP Notice: Undefined variable: i in \oc-content\plugins\invoice\admin\profiles.php on line 157
Plugin: v1.6.1
PHP: 7.2.34
Thanks!