CVE-2025-69210

FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.7, a stored cross-site scripting (XSS) vulnerability exists in the product file upload functionality. Authenticated users can upload crafted XML files containing executable JavaScript. These files are later rendered by the application without sufficient sanitization or content-type enforcement, allowing arbitrary JavaScript execution when the file is accessed. Because product files uploaded by regular users are visible to administrative users, this vulnerability can be leveraged to execute malicious JavaScript in an administrator’s browser session. Version 2025.7 fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:facturascripts:facturascripts:*:*:*:*:*:*:*:*

History

23 Feb 2026, 15:23

Type Values Removed Values Added
CPE cpe:2.3:a:facturascripts:facturascripts:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
First Time Facturascripts
Facturascripts facturascripts
References () https://facturascripts.com/publicaciones/ya-disponible-facturascripts-2025-7 - () https://facturascripts.com/publicaciones/ya-disponible-facturascripts-2025-7 - Release Notes
References () https://github.com/NeoRazorX/facturascripts/releases/tag/v2025.7 - () https://github.com/NeoRazorX/facturascripts/releases/tag/v2025.7 - Product, Release Notes
References () https://github.com/NeoRazorX/facturascripts/security/advisories/GHSA-2267-xqcf-gw2m - () https://github.com/NeoRazorX/facturascripts/security/advisories/GHSA-2267-xqcf-gw2m - Vendor Advisory

30 Dec 2025, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-30 20:16

Updated : 2026-02-23 15:23


NVD link : CVE-2025-69210

Mitre link : CVE-2025-69210

CVE.ORG link : CVE-2025-69210


JSON object : View

Products Affected

facturascripts

  • facturascripts
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')