Carlos Garcia
6 exploits
Active since Feb 2026
Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism
CVSS 7.2
FacturaScripts: Unstripped Image Metadata (EXIF) Leakage via Library Module File Upload/Download
CVSS 6.5
FacturaScripts: Reflected Cross-Site Scripting (XSS) via Cookie Manipulation
CVSS 3.9
FacturaScripts < 2025.8 - Reflected Cross-Site Scripting via Database Error Message
CVSS 5.4
FacturaScripts < 2025.81 - Authenticated SQL Injection via REST API Sort Parameter
CVSS 8.8
FacturaScripts < 2025.81 - Authenticated SQL Injection via Autocomplete CodeModel::all() Method
CVSS 8.8