Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Akaunting — Vulnerabilities & Security Advisories 14

Browse all 14 CVE security advisories affecting Akaunting. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Akaunting serves as an open-source accounting platform for small businesses and freelancers, handling financial data management and invoicing. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, often stemming from insufficient input validation and access control weaknesses. The platform's 7 recorded CVEs highlight recurring problems in areas like file upload mechanisms and user permission management. While no major public security incidents have been widely documented, the consistent pattern of vulnerabilities in its codebase suggests ongoing challenges in secure development practices, particularly for web application components handling sensitive financial operations.

Top products by Akaunting: Akaunting
CVE ID Title CVSS Severity Published
CVE-2022-51019 Akaunting before 2.1.31 OS Command Injection via app alias — akaunting CWE-78 8.8 High 2026-09-29
CVE-2026-19198 Akaunting 3.1.21 - Improper authorization in BulkActions handle dispatch — Akaunting CWE-863 8.7 High 2026-08-19
CVE-2026-16772 CVE-2026-16772 — Akaunting - - 2026-08-14
CVE-2026-71251 Akaunting - Cross-Company Media IDOR in Customer Portal Download Endpoint — akaunting CWE-639 6.5 Medium 2026-08-05
CVE-2026-11994 Akaunting 3.1.21 - Authenticated stored XSS in report description rendering — Akaunting CWE-79 - - 2026-06-22
CVE-2026-11943 Akaunting 3.1.21 - Authenticated stored XSS in document timeline — Akaunting CWE-79 - - 2026-06-22
CVE-2026-11942 Akaunting 3.1.21 - Stored XSS in delete confirmation modal — Akaunting CWE-79 - - 2026-06-22
CVE-2024-58293 Akaunting 3.1.8 Server-Side Template Injection via Multiple Form Fields — Akaunting CWE-1336 7.2AI High AI 2025-12-11
CVE-2021-36805 Akaunting Invoice Footer Persistent XSS — Akaunting CWE-79 5.2 Medium 2021-08-04
CVE-2021-36804 Akaunting Password Reset Relay — Akaunting CWE-640 5.4 Medium 2021-08-04
CVE-2021-36803 Akaunting Avatar Persistent XSS — Akaunting CWE-79 6.3 Medium 2021-08-04
CVE-2021-36802 Akaunting DoS via User-Controlled 'locale' Variable — Akaunting CWE-248 6.5 Medium 2021-08-04
CVE-2021-36801 Akaunting Authentication Bypass in Company Selection — Akaunting CWE-639 8.1 High 2021-08-04
CVE-2021-36800 Akaunting OS Command Injection in 'Money.php' — Akaunting CWE-94 8.7 High 2021-08-04

This page lists every published CVE security advisory associated with Akaunting. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.