Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-93454
Webkul Aureus ERP — Aureus ERP through 1.6.0 Stored XSS via Payment Term Note
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L P L L N 5.1 .0030 20.4 —
AFFECTED
Product Versions Fixed
Aureus ERP unspecified —
TIMELINE
Sep 17 Reserved by VulnCheck
Sep 17 Published (CNA: VulnCheck)
Sep 21 EXPLOIT PUBLISHED — CVE-2026-93454 (Webkul Aureus ERP). Public exploit reference added.
Description
Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitrary JavaScript to the payment-terms endpoint, which persists to the database and executes in browsers of all users viewing that Payment Term record.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| September 17, 2026 | Reserved | Reserved by VulnCheck |
| September 17, 2026 | Published | Published (CNA: VulnCheck) |
| September 21, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-93454 (Webkul Aureus ERP). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Webkul | Aureus ERP | Packagist | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-93454 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.