CVE-2026-23997 is a critical Stored Cross-Site Scripting (XSS) vulnerability affecting FacturaScripts versions 2025.71 and earlier. An attacker can inject malicious JavaScript into the "Observations" field, which is then executed in an administrator's browser when viewing the history. With a CVSS score of 9.0 (CRITICAL), this flaw allows for high impact to confidentiality, integrity, and availability due to improper HTML entity encoding. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2025.71CPE matchmatch criteria | cpe:2.3:a:facturascripts:facturascripts:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.6 Bluesky, 0.3 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.