Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'customerName', in 'a3factura-app.wolterskluwer.es/#/incomes/salesInvoices' endpoint, which could allow an attacker to execute arbitrary code in the victim's browser.

Project Subscriptions

Vendors Products
A3factura Subscribe
A3factura Subscribe
Advisories

No advisories yet.

Fixes

Solution

The fix has been deployed in production in version 4.114.0-rev.6, released on 17/02/2026.


Workaround

No workaround given by the vendor.

History

Thu, 26 Feb 2026 12:30:00 +0000

Type Values Removed Values Added
Description Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'customerName', in 'a3factura-app.wolterskluwer.es/#/incomes/salesInvoices' endpoint, which could allow an attacker to execute arbitrary code in the victim's browser.
Title Multiple vulnerabilities in A3factura software
First Time appeared A3factura
A3factura a3factura
Weaknesses CWE-79
CPEs cpe:2.3:a:a3factura:a3factura:4.111.2-rev.1:*:*:*:*:*:*:*
Vendors & Products A3factura
A3factura a3factura
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-02-26T12:18:13.402Z

Reserved: 2026-02-18T11:25:13.322Z

Link: CVE-2026-2679

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-26T13:16:17.080

Modified: 2026-02-26T13:16:17.080

Link: CVE-2026-2679

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses