CVE-2026-27964
LOWFacturaScripts: Reflected Cross-Site Scripting (XSS) via Cookie Manipulation
Title source: cnaDescription
FacturaScripts is an open source accounting and invoicing software. Versions 2025.7 and prior contain a Reflected Cross-Site Scripting (XSS) vulnerability through the fsNick cookie parameter. The application reflects the cookie's value directly into the HTML without sanitization. The fsNick cookie is rendered into the DOM without encoding. While the server does reject the modified session and forces a logout, the HTML containing the payload reaches the browser first. This lets the script execute immediately upon load, effectively beating the redirect. This issue has been fixed in version 2025.8.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/NeoRazorX/facturascripts/security/advisories/GHSA-gq5c-rw37-g46c
X_Refsource_Misc x_refsource_misc
https://github.com/NeoRazorX/facturascripts/commit/9066e10326029adf012114e27eb5f3f33f78ecfd
Scores
CVSS v3
3.9
EPSS
0.0010
EPSS Percentile
1.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (2)
facturascripts/facturascripts
0 - 2025.71Packagist
NeoRazorX/facturascripts
< 2025.8
Published
May 18, 2026
Tracked Since
May 19, 2026