SQL Injection Vulnerability in FacturaScripts Accounting Software by NeoRazorX
CVE-2026-25513
8.3HIGH
What is CVE-2026-25513?
FacturaScripts, an open-source ERP and accounting software, is susceptible to an SQL injection vulnerability in its REST API. This issue allows authenticated users to craft and execute arbitrary SQL queries through the sort parameter, due to insufficient validation of user-supplied input in the ModelClass::getOrderBy() method. Consequently, this affects all API endpoints that implement sorting functionalities. Users are advised to upgrade to version 2025.81 to mitigate this security risk.
Affected Version(s)
facturascripts < 2025.81
