Security Flaw in FacturaScripts Library Module Allows Exposure of Sensitive Metadata
CVE-2026-27892

6.5MEDIUM

Key Information:

Vendor

Neorazorx

Vendor
CVE Published:
18 May 2026

What is CVE-2026-27892?

The Library module in FacturaScripts, an open-source accounting and invoicing software, has a vulnerability that allows authenticated users to download images without any sanitization of embedded metadata. This results in the unfiltered presentation of sensitive information, including GPS coordinates and device details, to anyone with download access. For example, an employee uploading a personal image could unintentionally reveal their home address. This vulnerability specifically affects versions of FacturaScripts released prior to 2026 and has been remedied in the latest update.

Affected Version(s)

facturascripts < 2026

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.