CVE-2026-25513 | NeoRazorX facturascripts up to 2025.80 REST API ModelClass::getOrderBy sort sql injection (GHSA-cjfx-qhwm-hf99 / EUVD-2026-6094)
A vulnerability, which was classified as critical, was found in NeoRazorX facturascripts up to 2025.80. The affected element is the function ModelClass::getOrderBy of the component REST API. Executing a manipulation of the argument sort can lead to sql injection.
This vulnerability is handled as CVE-2026-25513. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.