Known Vulnerabilities for products from Akaunting
Listed below are 8 of the newest known vulnerabilities associated with the vendor "Akaunting".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-11994 json | Not Provided | 2026-06-22 | 2026-06-22 | |
| CVE-2026-11943 json | Not Provided | 2026-06-22 | 2026-06-22 | |
| CVE-2026-11942 json | Not Provided | 2026-06-22 | 2026-06-22 | |
| CVE-2026-8193 json | Not Provided | 2026-05-09 | 2026-05-09 | |
| CVE-2026-5568 json | Not Provided | 2026-04-05 | 2026-04-06 | |
| CVE-2021-36805 json | Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in the sale... | 4.8 - MEDIUM | 2021-08-04 | 2021-08-11 |
| CVE-2021-36804 json | Akaunting version 2.1.12 and earlier suffers from a password reset spoofing vulnerability, wherein an attacker can proxy pass... | 8.1 - HIGH | 2021-08-04 | 2021-08-13 |
| CVE-2021-36803 json | Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processi... | 5.4 - MEDIUM | 2021-08-04 | 2021-08-11 |
| CVE-2021-36802 json | Akaunting version 2.1.12 and earlier suffers from a denial-of-service issue that is triggered by setting a malformed 'locale'... | 6.5 - MEDIUM | 2021-08-04 | 2021-08-11 |
| CVE-2021-36801 json | Akaunting version 2.1.12 and earlier suffers from an authentication bypass issue in the user-controllable field, companies[0]... | 8.1 - HIGH | 2021-08-04 | 2021-08-11 |
| CVE-2021-36800 json | Akaunting version 2.1.12 and earlier suffers from a code injection issue in the Money.php component of the application. A POS... | 9.1 - CRITICAL | 2021-08-04 | 2021-08-11 |
| CVE-2020-22390 json | Akaunting <= 2.0.9 is vulnerable to CSV injection in the Item name field, export function. Attackers can inject arbitrary cod... | 8.8 - HIGH | 2021-06-21 | 2021-06-25 |
| CVE-2020-20908 json | Akaunting v1.3.17 was discovered to contain a stored cross-site scripting (XSS) vulnerability which allows attackers to execu... | 5.4 - MEDIUM | 2021-10-25 | 2021-10-28 |