CVE-2026-23476

MEDIUM

FacturaScripts <2025.8 - XSS

Title source: llm
STIX 2.1

Description

FacturaScripts is open-source enterprise resource planning and accounting software. Prior to 2025.8, there a reflected XSS bug in FacturaScripts. The problem is in how error messages get displayed. Twig's | raw filter is used, which skips HTML escaping. When triggering a database error (like passing a string where an integer is expected), the error message includes the input and gets rendered without sanitization. This vulnerability is fixed in 2025.8.

Scores

CVSS v3 5.4
EPSS 0.0002
EPSS Percentile 3.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
facturascripts/facturascripts < 2025.8
facturascripts/facturascripts 0 - 2025.81Packagist
Published Feb 02, 2026
Tracked Since Feb 18, 2026