SQL Injection Vulnerability in FacturaScripts Accounting Software by NeoRazorX
CVE-2026-25513

8.3HIGH

Key Information:

Vendor

Neorazorx

Vendor
CVE Published:
4 February 2026

What is CVE-2026-25513?

FacturaScripts, an open-source ERP and accounting software, is susceptible to an SQL injection vulnerability in its REST API. This issue allows authenticated users to craft and execute arbitrary SQL queries through the sort parameter, due to insufficient validation of user-supplied input in the ModelClass::getOrderBy() method. Consequently, this affects all API endpoints that implement sorting functionalities. Users are advised to upgrade to version 2025.81 to mitigate this security risk.

Affected Version(s)

facturascripts < 2025.81

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.