CVE-2026-93454EPSS p20.5%
CVE-2026-93454CVE-2026-93454
Description
Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitrary JavaScript to the payment-terms endpoint, which persists to the database and executes in browsers of all users viewing that Payment Term record.
Scoring
| CVSS | 5.4 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 0.30% probability of exploitation · percentile 20.5% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-22 |