Stored Cross-Site Scripting in FacturaScripts Accounting Software
CVE-2026-23997
8HIGH
What is CVE-2026-23997?
FacturaScripts, an open-source enterprise resource planning and accounting software, contains a vulnerability in the Observations field that allows for Stored Cross-Site Scripting (XSS). Found in versions 2025.71 and earlier, this flaw occurs in the History view where historical data is displayed without the necessary HTML entity encoding. As a result, an attacker could potentially execute arbitrary JavaScript in the administrators' browsers upon viewing this history, leading to unauthorized actions or data exposure.
Affected Version(s)
facturascripts <= 2025.71
