Логотип exploitDog
bind:CVE-2026-23997
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-23997

Количество 2

Количество 2

nvd логотип

CVE-2026-23997

6 дней назад

FacturaScripts is open-source enterprise resource planning and accounting software. In 2025.71 and earlier, a Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Observations field. The flaw occurs in the History view, where historical data is rendered without proper HTML entity encoding. This allows an attacker to execute arbitrary JavaScript in the browser of viewing the history by administrators.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-4v7v-7v7r-3r5h

6 дней назад

FacturaScripts has Stored Cross-Site Scripting (XSS) in "Observations" field via History View

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-23997

FacturaScripts is open-source enterprise resource planning and accounting software. In 2025.71 and earlier, a Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Observations field. The flaw occurs in the History view, where historical data is rendered without proper HTML entity encoding. This allows an attacker to execute arbitrary JavaScript in the browser of viewing the history by administrators.

CVSS3: 8
0%
Низкий
6 дней назад
github логотип
GHSA-4v7v-7v7r-3r5h

FacturaScripts has Stored Cross-Site Scripting (XSS) in "Observations" field via History View

CVSS3: 8
0%
Низкий
6 дней назад

Уязвимостей на страницу