CVE-2026-93454
Last modified
CVE-2026-93454 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitrary JavaScript to the payment-terms endpoint, which persists to the database and executes in browsers of all users viewing that Payment Term record..
Description
Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitrary JavaScript to the payment-terms endpoint, which persists to the database and executes in browsers of all users viewing that Payment Term record.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Webkul | Aureus ERP | <= 1.6.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-93454?
How severe is CVE-2026-93454?
How do I fix CVE-2026-93454?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9344A security vulnerability has been detected in Edimax EW-7438…8.8
- CVE-2026-9345A vulnerability was detected in Edimax EW-7438RPn up to 1.31…8.8
- CVE-2026-93450go-openapi/swag jsonutils before 0.27.1 contains a stack ove…7.5
- CVE-2026-93451snappy-java through 1.1.10.8 contains a buffer overflow vuln…6.5
- CVE-2026-93452snappy-java through 1.1.10.8 contains a buffer overflow vuln…7.5
- CVE-2026-93453SOGo before 5.12.11 constructs password-reset links using th…8.3
- CVE-2026-93455django-page-cms through 2.0.13 fails to properly validate pa…6.5
- CVE-2026-93456django-page-cms through 2.0.13 exempts five admin mutation v…8.2
- CVE-2026-9346A flaw has been found in Edimax EW-7438RPn up to 1.31. This …8.8
- CVE-2026-93467The OAKlouds developed by HGiga has a Insecure Deserializati…9.8
- CVE-2026-93468The OAKlouds developed by HGiga has an Arbitrary File Read v…7.5
- CVE-2026-9347A vulnerability has been found in Edimax EW-7438RPn up to 1.…6.3
Are you affected by CVE-2026-93454?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
