PKSA-tj9x-5rgg-xzgk Security Advisory
-
[LOW] FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=`
PKSA-tj9x-5rgg-xzgk CVE-2026-45710 GHSA-3x7p-v8hj-xh5m
Affected package: facturascripts/facturascripts
Affected version: <=2026.1
Reported by:
GitHub