Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 22 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 22 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the reusable delete confirmation flow. A user with permission to create or modify records, such as Items, can store HTML/JavaScript in the record name. | |
| Title | Akaunting 3.1.21 - Stored XSS in delete confirmation modal | |
| First Time appeared |
Akaunting
Akaunting akaunting |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:akaunting:akaunting:3.1.21:*:linux:*:*:*:*:* cpe:2.3:a:akaunting:akaunting:3.1.21:*:macos:*:*:*:*:* cpe:2.3:a:akaunting:akaunting:3.1.21:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Akaunting
Akaunting akaunting |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-06-22T16:27:09.388Z
Reserved: 2026-06-10T20:28:05.261Z
Link: CVE-2026-11942
Updated: 2026-06-22T16:27:03.947Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-22T17:45:05Z