Akaunting · Akaunting · CVE-2026-11942
**Name of the Vulnerable Software and Affected Versions**
Akaunting version 3.1.21
**Description**
An authenticated stored cross-site scripting issue exists in the reusable delete confirmation flow. A user with permissions to create or modify records, such as Items, can inject HTML or JavaScript into the record name.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.