๐Ÿ” CVE Alert

CVE-2026-104905

HIGH 8.1

FacturaScripts < 2026.7 PHP Object Injection via WidgetSelect

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

FacturaScripts before version 2026.7 contains a PHP object injection vulnerability in WidgetSelect::processFormData() that allows authenticated attackers to trigger unserialize() on raw POST data without an allowed_classes filter for multiple-select fields. Attackers can submit a serialized XLSXWriter object as the field value to invoke its __destruct() method, deleting arbitrary attacker-specified files such as config.php or backup data, resulting in denial of service and potential application reinstall hijack.

CWE CWE-502
Vendor neorazorx
Product facturascripts
Published Oct 5, 2026
Last Updated Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for neorazorx facturascripts

Be the first to know when new high vulnerabilities affecting neorazorx facturascripts are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High

Affected Versions

NeoRazorX / facturascripts
2025.7 < 2026.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/NeoRazorX/facturascripts/security/advisories/GHSA-p89j-gj6f-fh6g github.com: https://github.com/NeoRazorX/facturascripts/releases/tag/v2026.7 vulncheck.com: https://www.vulncheck.com/advisories/facturascripts-php-object-injection-via-widgetselect

Credits

Alisher Qarshibayev VulnCheck