SQL Injection Vulnerability in FacturaScripts Accounting Software
CVE-2026-25514
8.7HIGH
What is CVE-2026-25514?
FacturaScripts, an open-source enterprise resource planning and accounting software, is susceptible to an SQL injection vulnerability stemming from its autocomplete functionality. This issue allows authenticated attackers to inject malicious SQL commands through improperly sanitized user-supplied parameters in the CodeModel::all() method. Exploiting this vulnerability may enable unauthorized access to sensitive information stored in the database, including user credentials and configuration settings. It is critical to upgrade to version 2025.81 or later to mitigate this security risk.
Affected Version(s)
facturascripts < 2025.81
