---
id: CVE-2026-94387
title: >-
  Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability
  in the Chatter field-change log where old_value and new_value entries are
  rendered without proper escaping
summary: >-
  Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability
  in the Chatter field-change log where old_value and new_value entries are
  rendered without proper escaping. Any user permitted to edit tracked text
  fields can i…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: aureuserp
product: aureuserp
affected:
  - aureuserp < 1.6.0
published: '2026-09-21'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:08:55.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94387'
references:
  - url: 'https://github.com/aureuserp/aureuserp'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/aureuserp/aureuserp/blob/v1.5.0/plugins/webkul/chatter/resources/views/filament/infolists/components/messages/content-text-entry.blade.php#L165
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/aureuserp/aureuserp/blob/v1.5.0/plugins/webkul/chatter/resources/views/filament/infolists/components/messages/content-text-entry.blade.php#L182
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/aureuserp/aureuserp/commit/57cf5cf4c98d82a0ad89003402f27823fbe1e27c
    label: disclosure@vulncheck.com
  - url: 'https://github.com/aureuserp/aureuserp/pull/1465'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/aureuserp/aureuserp/releases/tag/v1.6.0'
    label: disclosure@vulncheck.com
  - url: 'https://hackmd.io/@leediay/stored-xss-aureuserp-chatter'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/aureus-erp-before-1.6.0-stored-xss-via-chatter-field-change-log
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00321
epssPercentile: 0.22542
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-21T15:17:05.399855Z'
ingestedAt: '2026-09-21T14:38:56.364Z'
---

## Overview

Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered without proper escaping. Any user permitted to edit tracked text fields can inject malicious markup that executes when other users, including administrators, view the record's Chatter panel.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
