CVE-2025-69210 - CVE House
Back to Database
Status published Low CVE-2025-69210

FacturaScripts vulnerable to Stored Cross-Site Scripting (XSS) via XML File Upload

Vulnerability Description

FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.7, a stored cross-site scripting (XSS) vulnerability exists in the product file upload functionality. Authenticated users can upload crafted XML files containing executable JavaScript. These files are later rendered by the application without sufficient sanitization or content-type enforcement, allowing arbitrary JavaScript execution when the file is accessed. Because product files uploaded by regular users are visible to administrative users, this vulnerability can be leveraged to execute malicious JavaScript in an administrator’s browser session. Version 2025.7 fixes the issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-69210

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

facturascripts
Vulnerable Versions:
< 2025.7

Timeline

Official Publish: December 30th, 2025
Last Modified: December 30th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)