PT-2026-30437 · Akaunting · Akaunting

Gabriel

·

Published

2026-04-05

·

Updated

2026-04-05

·

CVE-2026-5568

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Akaunting versions up to 3.1.21
Description Akaunting software is affected by a cross site scripting issue in the Invoice/Billing component. Manipulation of the notes argument can lead to exploitation. The issue is potentially exploitable remotely, and the exploit has been publicly disclosed. The vendor was contacted but did not respond.
Recommendations Update Akaunting to a version later than 3.1.21.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5568

Affected Products

Akaunting