CVE-2023-43139: Franfinance

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

An issue in franfinance before v.2.0.27 allows a remote attacker to execute arbitrary code via the validation.php, and controllers/front/validation.php components.

Affected products

  • Franfinance Franfinance: before 2.0.27 (fixed in 2.0.27); before 1.9.0 (fixed in 1.9.0)

Published 2023-10-31. Last modified 2026-06-17.