CVE-2026-23997

HIGH

FacturaScripts < 2025.71 - Stored Cross-Site Scripting in Observations Field History View

Title source: llm
STIX 2.1

Description

FacturaScripts is open-source enterprise resource planning and accounting software. In 2025.71 and earlier, a Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Observations field. The flaw occurs in the History view, where historical data is rendered without proper HTML entity encoding. This allows an attacker to execute arbitrary JavaScript in the browser of viewing the history by administrators.

References (1)

Core 1

Scores

CVSS v3 8.0
EPSS 0.0039
EPSS Percentile 30.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (2)
facturascripts/facturascripts < 2025.71
facturascripts/facturascripts 0Packagist
Published Feb 02, 2026
Tracked Since Feb 18, 2026