Medium severity6.1NVD Advisory· Published Feb 26, 2026· Updated Jun 17, 2026
CVE-2026-2680
CVE-2026-2680
Description
Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'customerVATNumber', in 'a3factura-app.wolterskluwer.es/#/incomes/salesDeliveryNotes' endpoint, which could allow an attacker to execute arbitrary code in the victim's browser.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:wolterskluwer:a3factura:4.111.2:rev.1:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:wolterskluwer:a3factura:4.111.2:rev.1:*:*:*:*:*:*
- (no CPE)
- Range: 4.111.2-rev.1
Patches
Vulnerability mechanics
References
1- www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-a3factura-softwarenvdThird Party Advisory
News mentions
0No linked articles in our index yet.