๐Ÿ” CVE Alert

CVE-2026-27964

LOW 3.9

FacturaScripts: Reflected Cross-Site Scripting (XSS) via Cookie Manipulation

CVSS Score
3.9
EPSS Score
0.0%
EPSS Percentile
0th

FacturaScripts is an open source accounting and invoicing software. Versions 2025.7 and prior contain a Reflected Cross-Site Scripting (XSS) vulnerability through the fsNick cookie parameter. The application reflects the cookie's value directly into the HTML without sanitization. The fsNick cookie is rendered into the DOM without encoding. While the server does reject the modified session and forces a logout, the HTML containing the payload reaches the browser first. This lets the script execute immediately upon load, effectively beating the redirect. This issue has been fixed in version 2025.8.

CWE CWE-79
Vendor neorazorx
Product facturascripts
Published May 18, 2026
Last Updated May 19, 2026
Stay Ahead of the Next One

Get instant alerts for neorazorx facturascripts

Be the first to know when new low vulnerabilities affecting neorazorx facturascripts are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

NeoRazorX / facturascripts
< 2025.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/NeoRazorX/facturascripts/security/advisories/GHSA-gq5c-rw37-g46c github.com: https://github.com/NeoRazorX/facturascripts/commit/9066e10326029adf012114e27eb5f3f33f78ecfd