Description
FacturaScripts before version 2026.7 contains a PHP object injection vulnerability in WidgetSelect::processFormData() that allows authenticated attackers to trigger unserialize() on raw POST data without an allowed_classes filter for multiple-select fields. Attackers can submit a serialized XLSXWriter object as the field value to invoke its __destruct() method, deleting arbitrary attacker-specified files such as config.php or backup data, resulting in denial of service and potential application reinstall hijack.
Published: 2026-10-05
Score: 6.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
Description FacturaScripts before version 2026.7 contains a PHP object injection vulnerability in WidgetSelect::processFormData() that allows authenticated attackers to trigger unserialize() on raw POST data without an allowed_classes filter for multiple-select fields. Attackers can submit a serialized XLSXWriter object as the field value to invoke its __destruct() method, deleting arbitrary attacker-specified files such as config.php or backup data, resulting in denial of service and potential application reinstall hijack.
Title FacturaScripts < 2026.7 PHP Object Injection via WidgetSelect
First Time appeared Neorazorx
Neorazorx facturascripts
Weaknesses CWE-502
CPEs cpe:2.3:a:neorazorx:facturascripts:*:*:*:*:*:*:*:*
Vendors & Products Neorazorx
Neorazorx facturascripts
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 6.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Neorazorx Facturascripts
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-05T18:01:58.256Z

Reserved: 2026-10-02T15:43:45.338Z

Link: CVE-2026-104905

cve-icon Vulnrichment

Updated: 2026-10-05T18:01:43.215Z

cve-icon NVD

Status : Received

Published: 2026-10-05T18:17:31.623

Modified: 2026-10-05T18:17:31.623

Link: CVE-2026-104905

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T18:30:19Z

Weaknesses