Back

MEDIUM

FOSSBilling has stored XSS in client email views via unescaped content in JavaScript template literal

Published Jul 6, 2026

Description

FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a stored cross-site scripting (XSS) vulnerability in the client-facing email history views of FOSSBilling. Email HTML content (`content_html`) is rendered into a JavaScript template literal using the `|raw` filter, bypassing all output escaping. An attacker with admin access can inject malicious JavaScript payloads into email content that execute in the browser of any client who views their email history. Version 0.8.0 contains a fix. Some workarounds are available. Restrict admin account access, audit email content in the database for suspicious payloads, and/or monitor client accounts for unusual activity.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 6, 2026
Updated Jul 8, 2026
Reserved Jun 9, 2026
CISA Vulnrichment
Updated Jul 8, 2026
NVD
Status Deferred
Modified Jul 8, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Jul 6, 2026
Updated Jul 8, 2026
Exploited since n/a
EUVD-2026-41966