Skip to main content

Threats Tagged 'cve-2026-23997'

View all threats tagged with 'cve-2026-23997'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-23997

Threats Tagged 'cve-2026-23997'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-23997 is a high-severity Stored Cross-Site Scripting (XSS) vulnerability affecting FacturaScripts versions 2025.71 and earlier. The flaw exists in the Observations field within the History view, where user input is rendered without proper HTML entity encoding, allowing attackers to inject and execute arbitrary JavaScript in the browsers of administrators viewing the history. Exploitation requires at least limited privileges to input data and some user interaction to trigger the payload. The vulnerability impacts confidentiality, integrity, and availability by enabling session hijacking, credential theft, or administrative account compromise. No known exploits are currently reported in the wild. European organizations using FacturaScripts for ERP and accounting functions are at risk, especially those with administrators accessing the affected History view. Mitigation requires applying patches once available, implementing strict input validation and output encoding, and restricting access to the History view to trusted users. Countries with significant SME adoption of FacturaScripts, such as Spain, Germany, France, Italy, and the UK, are most likely affected due to market penetration and the strategic importance of ERP systems. Given the CVSS 3.

Join the discussion

Showing 1 to 1 of 1 result

Filters:Tag: cve-2026-23997
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses