Product
Authenticated attackers can exploit a PHP object injection vulnerability in FacturaScripts versions prior to 2026.7 by injecting serialized objects into WidgetSelect multiple-select fields, leading to arbitrary file deletion.