Back to CVE List

CVE-2026-23997

HIGH SEVERITY

CVSS Score & Metrics

Base Score
8.0 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Vulnerability Description

FacturaScripts is open-source enterprise resource planning and accounting software. In 2025.71 and earlier, a Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Observations field. The flaw occurs in the History view, where historical data is rendered without proper HTML entity encoding. This allows an attacker to execute arbitrary JavaScript in the browser of viewing the history by administrators.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-79
Source
GitHub
Vendor
composer
Product
facturascripts/facturascripts

External References

Discussion (0)

Add Comment

No comments yet. Be the first!