📦 Facturascripts

by Facturascripts

🔍 What is Facturascripts?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-1715

CRITICAL CVSS 9.8 May 13, 2022

This vulnerability allows attackers to take over user accounts in FacturaScripts, an open-source billing and accounting software. Attackers can compromise accounts without authentication, potentially ...

CVE-2026-25514

HIGH CVSS 8.8 Feb 4, 2026

FacturaScripts contains a critical SQL injection vulnerability in the autocomplete functionality that allows authenticated attackers to extract sensitive data including user credentials, configuration...

CVE-2026-25513

HIGH CVSS 8.8 Feb 4, 2026

FacturaScripts contains a critical SQL injection vulnerability in its REST API that allows authenticated API users to execute arbitrary SQL queries through the sort parameter. This affects all API end...

CVE-2026-23997

HIGH CVSS 8.0 Feb 2, 2026

A stored XSS vulnerability in FacturaScripts allows attackers to inject malicious JavaScript into the Observations field, which executes when administrators view the History section. This affects all ...

CVE-2026-23476

MEDIUM CVSS 5.4 Feb 2, 2026

This reflected XSS vulnerability in FacturaScripts allows attackers to inject malicious scripts into error messages that get executed in users' browsers. It affects all FacturaScripts installations pr...

CVE-2025-69210

MEDIUM CVSS 5.4 Dec 30, 2025

FacturaScripts versions before 2025.7 contain a stored cross-site scripting (XSS) vulnerability in the file upload functionality. Authenticated users can upload malicious XML files containing JavaScri...