CVE-2026-11943: Akaunting 3.1.21 - Authenticated stored XSS in document timeline
Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the document timeline shown on invoice and bill detail pages. An authenticated user can store HTML/JavaScript in their own profile name.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11943?
The severity of CVE-2026-11943 is classified as medium with a CVSS score of 4.8.
What is CVE-2026-11943?
CVE-2026-11943 is an authenticated stored cross-site scripting vulnerability in Akaunting 3.1.21's document timeline allowing an authenticated user to store HTML/JavaScript.
How do I fix CVE-2026-11943?
To fix CVE-2026-11943, update Akaunting to the latest version where the vulnerability is patched.
Who is affected by CVE-2026-11943?
Authenticated users of Akaunting 3.1.21 are affected by CVE-2026-11943 due to the stored XSS vulnerability.
What type of vulnerability is CVE-2026-11943?
CVE-2026-11943 is categorized as a cross-site scripting (XSS) vulnerability.