Akaunting

Akaunting

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.8%
  • Veröffentlicht 29.09.2026 17:17:00
  • Zuletzt bearbeitet 29.09.2026 21:35:31

Akaunting before 2.1.31 contains an OS command injection vulnerability in the module installation and update flow where the alias parameter is passed unvalidated to shell command execution. Authenticated users with admin panel access can inject shell...

  • EPSS 0.24%
  • Veröffentlicht 19.08.2026 19:17:12
  • Zuletzt bearbeitet 28.08.2026 15:31:31

Akaunting 3.1.21 contains an authenticated improper authorization vulnerability in the common BulkActions dispatcher.This issue affects Akaunting: 3.1.21.

  • EPSS 0.2%
  • Veröffentlicht 14.08.2026 15:18:13
  • Zuletzt bearbeitet 14.09.2026 22:16:57

In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting full administrator privileges. This vulnerability is caused by a flaw in the `UpdateUser` job, which pro...

  • EPSS 0.2%
  • Veröffentlicht 05.08.2026 10:57:11
  • Zuletzt bearbeitet 26.08.2026 17:13:24

Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download, reachable at uploads/{id}/download behind only generic auth middleware) fetched the requested Media record by ID with no verification that it belonged to the reques...

  • EPSS 0.44%
  • Veröffentlicht 22.06.2026 15:37:58
  • Zuletzt bearbeitet 22.06.2026 19:16:39

Akaunting 3.1.21 contains an authenticated stored Cross-Site Scripting vulnerability in the report management workflow. A user with permission to create or update reports can store arbitrary HTML/JavaScript in the description field of a report.

  • EPSS 0.44%
  • Veröffentlicht 22.06.2026 15:30:36
  • Zuletzt bearbeitet 22.06.2026 18:16:31

Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the document timeline shown on invoice and bill detail pages. An authenticated user can store HTML/JavaScript in their own profile name.

  • EPSS 0.44%
  • Veröffentlicht 22.06.2026 15:18:29
  • Zuletzt bearbeitet 22.06.2026 18:16:31

Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the reusable delete confirmation flow. A user with permission to create or modify records, such as Items, can store HTML/JavaScript in the record name.

Exploit
  • EPSS 0.21%
  • Veröffentlicht 09.05.2026 18:45:08
  • Zuletzt bearbeitet 24.07.2026 08:10:00

A weakness has been identified in Akaunting 3.1.21. This issue affects some unknown processing of the file config/dompdf.php of the component Invoice PDF Rendering. Executing a manipulation can lead to server-side request forgery. The attack may be l...

  • EPSS 0.25%
  • Veröffentlicht 05.04.2026 13:17:14
  • Zuletzt bearbeitet 24.07.2026 09:10:00

A vulnerability has been found in Akaunting up to 3.1.21. This issue affects some unknown processing of the component Invoice/Billing. The manipulation of the argument notes leads to cross site scripting. The attack is possible to be carried out remo...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 11.12.2025 21:35:50
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Akaunting 3.1.8 contains a server-side template injection vulnerability that allows authenticated administrators to execute template expressions in multiple form input fields. Attackers can inject template payloads in items, taxes, transactions, and ...