Facturascripts is a narrowly focused accounting and invoicing application that, despite limited product scope, sits in a prominent position within small and medium business financial workflows. Vulnerabilities affecting the vendor skew toward serious outcomes and recur through web-facing input-handling and data-query weakness classes including cross-site scripting, SQL injection, improper input validation, and SQL command neutralization, reflecting the application's role as a server-side web platform processing untrusted client input. The vendor's disclosures frequently acquire public exploit code, consistent with the accessibility and business-critical nature of internet-exposed financial software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Facturascripts over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-69210MEDIUM FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.7, a stored cross-site scripting (XSS) vulnerability exists in the product | Dec 30, 2025 | 5.4 | 31 | NO | YES |
CVE-2022-1715CRITICAL Account Takeover in GitHub repository neorazorx/facturascripts prior to 2022.07. | May 13, 2022 | 9.8 | 29 | NO | NO |
CVE-2026-23997CRITICAL FacturaScripts is open-source enterprise resource planning and accounting software. In 2025.71 and earlier, a Stored Cross-Site Scripting (XSS) vulnerability was discovered in the | Feb 2, 2026 | 9.0 | 28 | NO | NO |
CVE-2026-25513HIGH FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScripts contains a critical SQL injection vulnerability in the | Feb 4, 2026 | 8.8 | 27 | NO | NO |
CVE-2026-25514HIGH FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScripts contains a critical SQL injection vulnerability in the | Feb 4, 2026 | 8.8 | 25 | NO | NO |
CVE-2022-1682MEDIUM Reflected Xss using url based payload in GitHub repository neorazorx/facturascripts prior to 2022.07. Xss can use to steal user's cookies which lead to Account takeover or do any m | May 12, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-2066MEDIUM Cross-site Scripting (XSS) - Reflected in GitHub repository neorazorx/facturascripts prior to 2022.06. | Jun 13, 2022 | 6.1 | 21 | NO | NO |
CVE-2022-1571MEDIUM Cross-site scripting - Reflected in Create Subaccount in GitHub repository neorazorx/facturascripts prior to 2022.07. This vulnerability can be arbitrarily executed javascript code | May 4, 2022 | 6.1 | 21 | NO | NO |
CVE-2026-23476MEDIUM FacturaScripts is open-source enterprise resource planning and accounting software. Prior to 2025.8, there a reflected XSS bug in FacturaScripts. The problem is in how error messag | Feb 2, 2026 | 5.4 | 20 | NO | NO |
CVE-2022-2065MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository neorazorx/facturascripts prior to 2022.06. | Jun 13, 2022 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Facturascripts.
Media articles that mention a CVE ID that affects a product developed by Facturascripts — matched by CVE ID, not by vendor name.