Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.1

Akaunting Invoice/Billing Notes Can Cause Remote Code Execution

CVE-2026-5568
Summary

A vulnerability in Akaunting's Invoice/Billing component allows attackers to inject malicious code into the system through the 'notes' field. This could allow an attacker to take control of a website. A fix is available, and you should update your Akaunting software as soon as possible.

Original title
A vulnerability has been found in Akaunting up to 3.1.21. This issue affects some unknown processing of the component Invoice/Billing. The manipulation of the argument notes leads to cross site scr...
Original description
A vulnerability has been found in Akaunting up to 3.1.21. This issue affects some unknown processing of the component Invoice/Billing. The manipulation of the argument notes leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
nvd CVSS2.0 4.0
nvd CVSS3.1 3.5
nvd CVSS4.0 5.1
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
CWE-94 Code Injection
Published: 5 Apr 2026 · Updated: 5 Apr 2026 · First seen: 5 Apr 2026