<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 14:24:37 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-322475</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-322475</link>
      <description>EUVD-2026-322475</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-322475</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42877</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42877</link>
      <description>&lt;p&gt;FacturaScripts is an open source accounting and invoicing software. In 2025.92 and earlier, a stored Cross-Site Scripting (XSS) vulnerability exists in the product search modal of sales (Core/Lib/AjaxForms/SalesModalHTML.php) and purchases documents (Core/Lib/AjaxForms/PurchasesModalHTML.php). An authenticated user with access to the warehouse module can create a product with a malicious reference that executes arbitrary JavaScript in the browser of any other user who opens the product search modal inside an invoice, order, or delivery note.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;FacturaScripts is an open source accounting and invoicing software. In 2025.92 and earlier, a stored Cross-Site Scripting (XSS) vulnerability exists in the product search modal of sales (Core/Lib/AjaxForms/SalesModalHTML.php) and purchases documents (Core/Lib/AjaxForms/PurchasesModalHTML.php). An authenticated user with access to the warehouse module can create a product with a malicious reference that executes arbitrary JavaScript in the browser of any other user who opens the product search modal inside an invoice, order, or delivery note.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42877</guid>
    </item>
    <item>
      <title>GHSA-r736-2678-fcrx — FacturaScripts vulnerable to stored XSS via product reference in sales/purchases</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r736-2678-fcrx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: facturascripts/facturascripts&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A stored Cross-Site Scripting (XSS) vulnerability exists in the product search modal of sales and purchases documents. An authenticated user with access to the warehouse module can create a product with a malicious reference that executes arbitrary JavaScript in the browser of any other user who opens the product search modal inside an invoice, order, or delivery note.&lt;/p&gt;
&lt;p&gt;## Affected files&lt;/p&gt;
&lt;p&gt;- `Core/Lib/AjaxForms/SalesModalHTML.php`
- `Core/Lib/AjaxForms/PurchasesModalHTML.php`&lt;/p&gt;
&lt;p&gt;## Vulnerability details&lt;/p&gt;
&lt;p&gt;The `referencia` field of a product variant is injected directly into an HTML `onclick` attribute string without JavaScript context escaping:&lt;/p&gt;
&lt;p&gt;```php
// SalesModalHTML.php ~line 102
$tbody .= &amp;#39;&amp;lt;tr onclick=&amp;#34;return salesFormAction(\&amp;#39;add-product\&amp;#39;, \&amp;#39;&amp;#39;
    . $row[&amp;#39;referencia&amp;#39;]   // no htmlspecialchars() applied
    . &amp;#39;\&amp;#39;);&amp;#34;&amp;gt;&amp;#39;;
```&lt;/p&gt;
&lt;p&gt;When a product is saved, `noHtml()` encodes `&amp;#39;` → `&amp;amp;#39;`. This appears safe in static HTML context. However, the modal HTML is later returned as a JSON response and inserted into the DOM via `innerHTML`:&lt;/p&gt;
&lt;p&gt;```javascript
// SalesDocument.html.twig line 118
document.getElementById(&amp;#34;findProductList&amp;#34;).innerHTML = data.products;
```&lt;/p&gt;
&lt;p&gt;The browser HTML parser decodes `&amp;amp;#39;` → `&amp;#39;` during the `innerHTML` assignment, breaking out of the JavaScript string literal in the `onclick` attribute and executing the injected code.&lt;/p&gt;
&lt;p&gt;**Attack payload stored in database:** `x&amp;amp;#39;+alert(1)+&amp;amp;#39;`&lt;/p&gt;
&lt;p&gt;**Resulting `onclick` after `innerHTML` decode:**
```javascript
re…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: facturascripts/facturascripts&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A stored Cross-Site Scripting (XSS) vulnerability exists in the product search modal of sales and purchases documents. An authenticated user with access to the warehouse module can create a product with a malicious reference that executes arbitrary JavaScript in the browser of any other user who opens the product search modal inside an invoice, order, or delivery note.&lt;/p&gt;
&lt;p&gt;## Affected files&lt;/p&gt;
&lt;p&gt;- `Core/Lib/AjaxForms/SalesModalHTML.php`
- `Core/Lib/AjaxForms/PurchasesModalHTML.php`&lt;/p&gt;
&lt;p&gt;## Vulnerability details&lt;/p&gt;
&lt;p&gt;The `referencia` field of a product variant is injected directly into an HTML `onclick` attribute string without JavaScript context escaping:&lt;/p&gt;
&lt;p&gt;```php
// SalesModalHTML.php ~line 102
$tbody .= &amp;#39;&amp;lt;tr onclick=&amp;#34;return salesFormAction(\&amp;#39;add-product\&amp;#39;, \&amp;#39;&amp;#39;
    . $row[&amp;#39;referencia&amp;#39;]   // no htmlspecialchars() applied
    . &amp;#39;\&amp;#39;);&amp;#34;&amp;gt;&amp;#39;;
```&lt;/p&gt;
&lt;p&gt;When a product is saved, `noHtml()` encodes `&amp;#39;` → `&amp;amp;#39;`. This appears safe in static HTML context. However, the modal HTML is later returned as a JSON response and inserted into the DOM via `innerHTML`:&lt;/p&gt;
&lt;p&gt;```javascript
// SalesDocument.html.twig line 118
document.getElementById(&amp;#34;findProductList&amp;#34;).innerHTML = data.products;
```&lt;/p&gt;
&lt;p&gt;The browser HTML parser decodes `&amp;amp;#39;` → `&amp;#39;` during the `innerHTML` assignment, breaking out of the JavaScript string literal in the `onclick` attribute and executing the injected code.&lt;/p&gt;
&lt;p&gt;**Attack payload stored in database:** `x&amp;amp;#39;+alert(1)+&amp;amp;#39;`&lt;/p&gt;
&lt;p&gt;**Resulting `onclick` after `innerHTML` decode:**
```javascript
re…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r736-2678-fcrx</guid>
    </item>
  </channel>
</rss>
