CVE-2026-53641

FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a stored cross-site scripting (XSS) vulnerability in the client-facing email history views of FOSSBilling. Email HTML content (`content_html`) is rendered into a JavaScript template literal using the `|raw` filter, bypassing all output escaping. An attacker with admin access can inject malicious JavaScript payloads into email content that execute in the browser of any client who views their email history. Version 0.8.0 contains a fix. Some workarounds are available. Restrict admin account access, audit email content in the database for suspicious payloads, and/or monitor client accounts for unusual activity.
CVSS

No CVSS.

Configurations

No configuration.

History

06 Jul 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-06 23:16

Updated : 2026-07-08 20:16


NVD link : CVE-2026-53641

Mitre link : CVE-2026-53641

CVE.ORG link : CVE-2026-53641


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-838

Inappropriate Encoding for Output Context