pkg:Packagist/facturascripts/facturascripts

共 20 筆 CVECRITICAL2HIGH2MEDIUM12LOW1

✅ 檢查你的版本

所有已知漏洞

  • CRITICAL9.8CVE-2022-1715Account takeover in facturascripts
    from 0, < 2022.08
  • CRITICAL9.0CVE-2022-1514Cross site scripting in FacturaScripts
    from 0, < 2022.06
  • HIGH8.0CVE-2026-23997FacturaScripts has Stored Cross-Site Scripting (XSS) in "Observations" field via History View
    from 0, <= 2025.71
  • HIGH7.2CVE-2026-27891FacturaScripts Vulnerable to Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism
    from 0, <= 2025.71
  • MEDIUM6.5CVE-2026-27892FacturaScripts Vulnerable to Unstripped Image Metadata (EXIF) Leakage via Library Module File Upload/Download
    from 0, <= 2025.81
  • MEDIUM6.5CVE-2022-1988Cross-site Scripting in FacturaScripts
    from 0, <= 2022.08
  • MEDIUM6.3CVE-2026-42879FacturaScripts Vulnerable to Authenticated Remote Code Execution (RCE) via GIF Image Upload in Product Images
    from 0, <= 2025.81
  • MEDIUM6.1CVE-2022-2066Cross site scripting in facturascripts
    from 0, < 2022.06
  • MEDIUM6.1CVE-2022-1682Cross-site Scripting in facturascripts
    from 0, < 2022.08
  • MEDIUM6.1CVE-2022-1571Cross-site Scripting in FacturaScripts
    from 0, < 2022.07
  • MEDIUM5.4CVE-2026-42877FacturaScripts vulnerable to stored XSS via product reference in sales/purchases
    from 0, <= 2025.92
  • MEDIUM5.4CVE-2026-23476FacturaScripts is Vulnerable to Reflected XSS
    from 0, < 2025.81
  • MEDIUM5.4CVE-2022-2065Cross-site Scripting in FacturaScripts
    from 0, < 2022.06
  • MEDIUM5.4CVE-2022-2016Cross-site Scripting in FacturaScripts
    from 0, <= 2022.08
  • MEDIUM5.3CVE-2026-42878FacturaScripts Vulnerable to Unauthenticated phpinfo() Disclosure via Installer Endpoint
    >= 2026, <= 2026.1
  • MEDIUM4.3CVE-2026-32699FacturaScripts has Insecure Parameter Handling: Unauthorized Modification of Immutable 'nick' Field
    from 0, <= 2024.92.x-dev
  • LOW3.9CVE-2026-27964FacturaScripts vulnerable to Reflected Cross-Site Scripting (XSS) via Cookie Manipulation
    from 0, <= 2025.71
  • CVE-2026-25514FacturaScripts has SQL Injection in Autocomplete Actions
    from 0, < 2025.81
  • CVE-2026-25513FacturaScripts has SQL Injection in API ORDER BY Clause
    from 0, < 2025.81
  • CVE-2025-69210FacturaScripts is Vulnerable to Stored Cross-Site Scripting (XSS) via XML File Upload
    from 0, < 2025.7