PT-2026-51328 · Akaunting+1 · Akaunting

·

CVE-2026-11943

·

Published

2026-06-22

·

Updated

2026-06-22

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Akaunting version 3.1.21
Description An authenticated stored cross-site scripting (XSS) issue exists in the document timeline displayed on invoice and bill detail pages. This occurs when an authenticated user stores malicious HTML or JavaScript within their profile name.
Recommendations Update Akaunting to a version newer than 3.1.21.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11943

Affected Products

Akaunting