๐Ÿ” CVE Alert

CVE-2026-93454

MEDIUM 5.4

Aureus ERP through 1.6.0 Stored XSS via Payment Term Note

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitrary JavaScript to the payment-terms endpoint, which persists to the database and executes in browsers of all users viewing that Payment Term record.

CWE CWE-79
Vendor webkul
Product aureus erp
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for webkul aureus erp

Be the first to know when new medium vulnerabilities affecting webkul aureus erp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Webkul / Aureus ERP
0 โ‰ค 1.6.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/aureuserp/aureuserp/pull/1562 hackmd.io: https://hackmd.io/@leediay/stored-xss-aureus-via-payment-term github.com: https://github.com/aureuserp/aureuserp/blob/v1.6.0/plugins/webkul/accounts/src/Filament/Resources/PaymentTermResource/Schemas/PaymentTermInfolist.php#L59 github.com: https://github.com/aureuserp/aureuserp vulncheck.com: https://www.vulncheck.com/advisories/aureus-erp-through-1.6.0-stored-xss-via-payment-term-note

Credits

leediay153