FacturaScripts before version 2026.7 contains a PHP object injection vulnerability in WidgetSelect::processFormData() that allows authenticated attackers to trigger unserialize() on raw POST data without an allowed_classes filter for multiple-select fields. Attackers can submit a serialized XLSXWriter object as the field value to invoke its __destruct() method, deleting arbitrary attacker-specified files such as config.php or backup data, resulting in denial of service and potential application reinstall hijack.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 05 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
Description FacturaScripts before version 2026.7 contains a PHP object injection vulnerability in WidgetSelect::processFormData() that allows authenticated attackers to trigger unserialize() on raw POST data without an allowed_classes filter for multiple-select fields. Attackers can submit a serialized XLSXWriter object as the field value to invoke its __destruct() method, deleting arbitrary attacker-specified files such as config.php or backup data, resulting in denial of service and potential application reinstall hijack.
Title FacturaScripts < 2026.7 PHP Object Injection via WidgetSelect
First Time appeared Neorazorx
Neorazorx facturascripts
Weaknesses CWE-502
CPEs cpe:2.3:a:neorazorx:facturascripts:*:*:*:*:*:*:*:*
Vendors & Products Neorazorx
Neorazorx facturascripts
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 6.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-05T18:01:58.256Z

Reserved: 2026-10-02T15:43:45.338Z

Link: CVE-2026-104905

cve-icon Vulnrichment

Updated: 2026-10-05T18:01:43.215Z

cve-icon NVD

Status : Received

Published: 2026-10-05T18:17:31.623

Modified: 2026-10-05T18:17:31.623

Link: CVE-2026-104905

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T18:30:19Z

Weaknesses