Known Vulnerabilities for Akaunting by Akaunting
Listed below are 8 of the newest known vulnerabilities associated with "Akaunting" by "Akaunting".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-71251 json | Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download, reachable at uploads/{id}/download behi... | Not Provided | 2026-08-05 | 2026-08-10 |
| CVE-2026-16772 json | In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the a... | Not Provided | 2026-08-14 | 2026-08-14 |
| CVE-2026-11994 json | Akaunting 3.1.21 contains an authenticated stored Cross-Site Scripting vulnerability in the report management workflow. A use... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-11943 json | Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the document timeline shown on invoic... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-11942 json | Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the reusable delete confirmation flow... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2021-36805 json | Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in the sale... | 4.8 - MEDIUM | 2021-08-04 | 2021-08-11 |
| CVE-2021-36804 json | Akaunting version 2.1.12 and earlier suffers from a password reset spoofing vulnerability, wherein an attacker can proxy pass... | 8.1 - HIGH | 2021-08-04 | 2021-08-13 |
| CVE-2021-36803 json | Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processi... | 5.4 - MEDIUM | 2021-08-04 | 2021-08-11 |
| CVE-2021-36802 json | Akaunting version 2.1.12 and earlier suffers from a denial-of-service issue that is triggered by setting a malformed 'locale'... | 6.5 - MEDIUM | 2021-08-04 | 2021-08-11 |
| CVE-2021-36801 json | Akaunting version 2.1.12 and earlier suffers from an authentication bypass issue in the user-controllable field, companies[0]... | 8.1 - HIGH | 2021-08-04 | 2021-08-11 |