
CVE-2026-26460 A HTML Injection vulnerability exists in the Dashboard module of Vtiger CRM 8.4.0. The application fails to properly neutralize user-supplied input in the tabid param… https://www.cve.org/CVERecord?id=CVE-2026-26460
Post summary
A CVE (CVE-2026-26460) has been announced for Vtiger CRM 8.4.0, detailing an HTML Injection flaw in its Dashboard module that fails to sanitize the tabid parameter.

