FacturaScripts是西班牙Carlos Garcia个人开发者的一个开源 ERP 软件。 FacturaScripts 2026之前版本存在信息泄露漏洞,该漏洞源于Library模块未清理上传图像的EXIF/XMP/IPTC元数据,可能导致敏感信息泄露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| NeoRazorX | facturascripts | < 2026 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| NeoRazorX | facturascripts | < 2026 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-27891 | 7.2 HIGH | Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism |
| CVE-2026-27964 | 3.9 LOW | FacturaScripts: Reflected Cross-Site Scripting (XSS) via Cookie Manipulation |
No comments yet