Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the document timeline shown on invoice and bill detail pages. An authenticated user can store HTML/JavaScript in their own profile name.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 22 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the document timeline shown on invoice and bill detail pages. An authenticated user can store HTML/JavaScript in their own profile name. | |
| Title | Akaunting 3.1.21 - Authenticated stored XSS in document timeline | |
| First Time appeared |
Akaunting
Akaunting akaunting |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:akaunting:akaunting:3.1.21:*:linux:*:*:*:*:* cpe:2.3:a:akaunting:akaunting:3.1.21:*:macos:*:*:*:*:* cpe:2.3:a:akaunting:akaunting:3.1.21:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Akaunting
Akaunting akaunting |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-06-22T15:32:35.425Z
Reserved: 2026-06-10T20:45:07.142Z
Link: CVE-2026-11943
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-22T16:30:08Z
Weaknesses