CVE-2026-23997
Last modified
CVE-2026-23997 is a critical-severity vulnerability rated 9/10 on the CVSS scale. FacturaScripts is open-source enterprise resource planning and accounting software. In 2025.71 and earlier, a Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Observations field. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
FacturaScripts is open-source enterprise resource planning and accounting software. In 2025.71 and earlier, a Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Observations field. The flaw occurs in the History view, where historical data is rendered without proper HTML entity encoding. This allows an attacker to execute arbitrary JavaScript in the browser of viewing the history by administrators.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Facturascripts | Facturascripts | < 2025.71 |
References
- https://github.com/NeoRazorX/facturascripts/security/advisories/GHSA-4v7v-7v7r-3r5hExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-23997?
How severe is CVE-2026-23997?
How do I fix CVE-2026-23997?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-2399CWE-22 Improper Limitation of a Pathname to a Restricted Dir…6.1
- CVE-2026-23990The Flux Operator is a Kubernetes CRD controller that manage…5.3
- CVE-2026-23991go-tuf is a Go implementation of The Update Framework (TUF).…7.5
- CVE-2026-23992go-tuf is a Go implementation of The Update Framework (TUF).…7.5
- CVE-2026-23995EVerest is an EV charging software stack. Prior to version 2…7.8
- CVE-2026-23996FastAPI Api Key provides a backend-agnostic library that pro…3.7
- CVE-2026-23998Fleet is open source device management software. Prior to ve…7.5
- CVE-2026-23999Fleet is open source device management software. In versions…5.5
- CVE-2026-2400CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Inje…4.3
- CVE-2026-24000Fleet is open source device management software. Prior to ve…5.3
- CVE-2026-24001jsdiff is a JavaScript text differencing implementation. Pri…7.5
- CVE-2026-24002Grist is spreadsheet software using Python as its formula la…9.6
Are you affected by CVE-2026-23997?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
