facturascripts/facturascripts Security Advisories for v2022.08 (18)
-
[LOW] FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=`
PKSA-tj9x-5rgg-xzgk CVE-2026-45710 GHSA-3x7p-v8hj-xh5m
Affected version: <=2026.1
Reported by:
GitHub -
[HIGH] FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens the export
PKSA-9nsq-164p-6ppm CVE-2026-45263 GHSA-2p5x-4jr6-x5jg
Affected version: <=2026.1
Reported by:
GitHub -
[HIGH] FacturaScripts: Unauthenticated Path Traversal in Static File Controllers Reads Private MyFiles Documents
PKSA-cphp-d9mj-j5ny CVE-2026-45693 GHSA-cv65-7cg8-r623
Affected version: <=2026.2
Reported by:
GitHub -
[CRITICAL] FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn`
PKSA-582m-pjr9-1vy2 CVE-2026-45262 GHSA-5qmh-x653-g8qj
Affected version: <=2026.1
Reported by:
GitHub -
[CRITICAL] FacturaScripts: Account takeover of any 2FA-enabled user
PKSA-dn8k-128k-8cz7 CVE-2026-47677 GHSA-c67f-gmxw-mj93
Affected version: <=2026.2
Reported by:
GitHub -
[MEDIUM] FacturaScripts Vulnerable to Authenticated Remote Code Execution (RCE) via GIF Image Upload in Product Images
PKSA-rs14-58cq-g5jg CVE-2026-42879 GHSA-vf3q-frmr-vrr9
Affected version: <=2025.81
Reported by:
GitHub -
[MEDIUM] FacturaScripts vulnerable to stored XSS via product reference in sales/purchases
PKSA-1ktk-zddg-2f2s CVE-2026-42877 GHSA-r736-2678-fcrx
Affected version: <=2025.92
Reported by:
GitHub -
[LOW] FacturaScripts vulnerable to Reflected Cross-Site Scripting (XSS) via Cookie Manipulation
PKSA-qm4y-jdfc-4pmf CVE-2026-27964 GHSA-gq5c-rw37-g46c
Affected version: <=2025.71
Reported by:
GitHub -
[MEDIUM] FacturaScripts Vulnerable to Unstripped Image Metadata (EXIF) Leakage via Library Module File Upload/Download
PKSA-zck8-p11k-g1qj CVE-2026-27892 GHSA-q7f2-rv22-2xgr
Affected version: <=2025.81
Reported by:
GitHub -
[HIGH] FacturaScripts Vulnerable to Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism
PKSA-xfzw-dtp7-gwj8 CVE-2026-27891 GHSA-3pgc-xqg9-cfr6
Affected version: <=2025.71
Reported by:
GitHub -
[MEDIUM] FacturaScripts has Insecure Parameter Handling: Unauthorized Modification of Immutable 'nick' Field
PKSA-8tbv-2p1s-9wnk CVE-2026-32699 GHSA-pp79-hqv6-vmc3
Affected version: <=2024.92.x-dev
Reported by:
GitHub -
[HIGH] FacturaScripts has SQL Injection in Autocomplete Actions
PKSA-gc7x-dnq3-tkv9 CVE-2026-25514 GHSA-pqqg-5f4f-8952
Affected version: <2025.81
Reported by:
GitHub -
[HIGH] FacturaScripts has SQL Injection in API ORDER BY Clause
PKSA-tnd6-5wk6-f448 CVE-2026-25513 GHSA-cjfx-qhwm-hf99
Affected version: <2025.81
Reported by:
GitHub -
[HIGH] FacturaScripts has Stored Cross-Site Scripting (XSS) in "Observations" field via History View
PKSA-xpcq-5crs-c78v CVE-2026-23997 GHSA-4v7v-7v7r-3r5h
Affected version: <=2025.71
Reported by:
GitHub -
[MEDIUM] FacturaScripts is Vulnerable to Reflected XSS
PKSA-qkt1-mscz-6n4p CVE-2026-23476 GHSA-g6w2-q45f-xrp4
Affected version: <2025.81
Reported by:
GitHub -
[HIGH] FacturaScripts is Vulnerable to Stored Cross-Site Scripting (XSS) via XML File Upload
PKSA-5rds-6cgc-6zg4 CVE-2025-69210 GHSA-2267-xqcf-gw2m
Affected version: <=2025.4|=2025.43|=2025.41|=2025.11
Reported by:
GitHub -
[MEDIUM] Cross-site Scripting in FacturaScripts
PKSA-y9jr-nh92-xscm CVE-2022-2016 GHSA-j8c7-3jpq-8985
Affected version: <=2022.08
Reported by:
GitHub -
[MEDIUM] Cross-site Scripting in FacturaScripts
PKSA-8jw7-xw28-wxz7 CVE-2022-1988 GHSA-r7jw-mg27-j839
Affected version: <=2022.08
Reported by:
GitHub