CVE-2026-53641
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a stored cross-site scripting (XSS) vulnerability in the client-facing email history views of FOSSBilling. Email HTML content (`content_html`) is rendered into a JavaScript template literal using the `|raw` filter, bypassing all output escaping. An attacker with admin access can inject malicious JavaScript payloads into email content that execute in the browser of any client who views their email history. Version 0.8.0 contains a fix. Some workarounds are available. Restrict admin account access, audit email content in the database for suspicious payloads, and/or monitor client accounts for unusual activity.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
- EPSS probability
- 0.44%
- CWE
- CWE-79, CWE-838
- Published
- 2026-07-06
- Last modified
- 2026-07-08
Affected products
- FOSSBilling FOSSBilling
Weakness type
Related vulnerabilities
- CVE-2026-89268 — QloApps through 1.7.0 Reflected XSS via List Filter Parameters
- CVE-2026-90443 — A web interface reflects a portion of the request URL into a script context and a hyperlink...
- CVE-2026-54165 — Stored DOM-XSS in public shared-folder image gallery (one-click, unauthenticated victim)
- CVE-2026-81918 — Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block
- CVE-2026-81917 — Concrete CMS below 9.5.3 is vulnerable to Stored XSS in the Document Library block file description and tags
- CVE-2026-77490 — Microsoft Edge (Chromium-based) Spoofing Vulnerability
- CVE-2026-81911 — Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot save_template via Unescaped Summary Description
- CVE-2026-62138 — WordPress Visual Composer Website Builder plugin <= 45.16.1 - Cross Site Scripting (XSS) vulnerability