Akaunting

Akaunting

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 19.08.2026 19:17:12
  • Zuletzt bearbeitet 19.08.2026 20:17:14

Akaunting 3.1.21 contains an authenticated improper authorization vulnerability in the common BulkActions dispatcher.This issue affects Akaunting: 3.1.21.

  • EPSS 0.2%
  • Veröffentlicht 14.08.2026 15:18:13
  • Zuletzt bearbeitet 14.08.2026 20:16:49

In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting full administrator privileges. This vulnerability is caused by a flaw in the `UpdateUser` job, which pro...

  • EPSS 0.2%
  • Veröffentlicht 05.08.2026 10:57:11
  • Zuletzt bearbeitet 10.08.2026 12:17:27

Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download, reachable at uploads/{id}/download behind only generic auth middleware) fetched the requested Media record by ID with no verification that it belonged to the reques...

  • EPSS 0.44%
  • Veröffentlicht 22.06.2026 15:37:58
  • Zuletzt bearbeitet 22.06.2026 19:16:39

Akaunting 3.1.21 contains an authenticated stored Cross-Site Scripting vulnerability in the report management workflow. A user with permission to create or update reports can store arbitrary HTML/JavaScript in the description field of a report.

  • EPSS 0.44%
  • Veröffentlicht 22.06.2026 15:30:36
  • Zuletzt bearbeitet 22.06.2026 18:16:31

Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the document timeline shown on invoice and bill detail pages. An authenticated user can store HTML/JavaScript in their own profile name.

  • EPSS 0.44%
  • Veröffentlicht 22.06.2026 15:18:29
  • Zuletzt bearbeitet 22.06.2026 18:16:31

Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the reusable delete confirmation flow. A user with permission to create or modify records, such as Items, can store HTML/JavaScript in the record name.

Exploit
  • EPSS 0.21%
  • Veröffentlicht 09.05.2026 18:45:08
  • Zuletzt bearbeitet 24.07.2026 08:10:00

A weakness has been identified in Akaunting 3.1.21. This issue affects some unknown processing of the file config/dompdf.php of the component Invoice PDF Rendering. Executing a manipulation can lead to server-side request forgery. The attack may be l...

  • EPSS 0.25%
  • Veröffentlicht 05.04.2026 13:17:14
  • Zuletzt bearbeitet 24.07.2026 09:10:00

A vulnerability has been found in Akaunting up to 3.1.21. This issue affects some unknown processing of the component Invoice/Billing. The manipulation of the argument notes leads to cross site scripting. The attack is possible to be carried out remo...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 11.12.2025 21:35:50
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Akaunting 3.1.8 contains a server-side template injection vulnerability that allows authenticated administrators to execute template expressions in multiple form input fields. Attackers can inject template payloads in items, taxes, transactions, and ...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 21.08.2025 17:15:31
  • Zuletzt bearbeitet 10.09.2025 20:02:08

Cross-site scripting (XSS) vulnerability in the component /common/reports of Akaunting v3.1.18 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name parameter.