CVE-2026-93454
Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitrary JavaScript to the payment-terms endpoint, which persists to the database and executes in browsers of all users viewing that Payment Term record.
- Published Sep 18, 2026
- CVSS 5.1 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)