PT-2026-38612 · Neorazorx+1 · Facturascripts+1

Published

2026-05-07

·

Updated

2026-05-19

·

CVE-2026-27964

CVSS v3.1

3.9

Low

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions FacturaScripts versions prior to 2025.8
Description A Reflected Cross-Site Scripting (XSS) issue exists where the application reflects the value of the fsNick cookie parameter directly into the HTML without sanitization or encoding into the Document Object Model (DOM). Although the server rejects the modified session and forces a logout, the HTML containing the payload reaches the browser first, allowing the script to execute immediately upon load and bypass the redirect.
Recommendations Update to version 2025.8. As a temporary workaround, restrict or sanitize the use of the fsNick cookie parameter to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-27964
GHSA-GQ5C-RW37-G46C

Affected Products

Facturascripts
Facturascripts/Facturascripts