Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-23476

Опубликовано: 02 фев. 2026
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

FacturaScripts is open-source enterprise resource planning and accounting software. Prior to 2025.8, there a reflected XSS bug in FacturaScripts. The problem is in how error messages get displayed. Twig's | raw filter is used, which skips HTML escaping. When triggering a database error (like passing a string where an integer is expected), the error message includes the input and gets rendered without sanitization. This vulnerability is fixed in 2025.8.

EPSS

Процентиль: 1%
0.0001
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
github
5 дней назад

FacturaScripts is Vulnerable to Reflected XSS

EPSS

Процентиль: 1%
0.0001
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79