PT-2026-56034 · Unknown · Fossbilling

·

CVE-2026-53641

·

Published

2026-07-06

·

Updated

2026-07-08

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions FOSSBilling versions 0.6.0 through 0.7.2
Description A stored cross-site scripting (XSS) issue exists in the client-facing email history views. This occurs because email HTML content, specifically the content html variable, is rendered into a JavaScript template literal using the |raw filter, which bypasses output escaping. An attacker with administrative privileges can inject malicious JavaScript payloads into email content that will execute in the browser of any client viewing their email history.
Recommendations Update to version 0.8.0. Restrict admin account access. Audit email content in the database for suspicious payloads. Monitor client accounts for unusual activity.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53641
GHSA-Q6C8-6R72-35F7

Affected Products

Fossbilling