CVE-2026-32754Disclosure(freescout / freescout)

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch freescout freescout systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.208 and below are vulnerable to Stored Cross-Site Scripting (XSS) through FreeScout's email notification templates. Incoming email bodies are stored in the database without sanitization and rendered unescaped in outgoing email notifications using Blade's raw output syntax {!! $thread->body !!}. An unauthenticated attacker can exploit this vulnerability by simply sending an email, and when opened by any subscribed agent or admin as part of their normal workflow, enabling universal HTML injection (phishing, tracking) and, in vulnerable email clients, JavaScript execution (session hijacking, credential theft, account takeover) affecting all recipients simultaneously. This issue has been fixed in version 1.8.209.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-116

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freescout

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-19); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
freescout

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-19: 3Mentions · 2026-03-20: 2Patch / Workaround · 2026-03-19: 1Technical Details · 2026-03-19: 3Technical Details · 2026-03-20: 203-1903-20
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-193
Disclosure2Patch1
2026-03-202
Disclosure2
Full discourse5 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-32754 - Critical FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.208 and below are vulnerable to Stored Cross-Site Scripting (XSS) through FreeScout's email... https://www.thehackerwire.com/vulnerability/CVE-2026-32754/ https://t.co/M8Pf1aDfVX

    Post summary

    The tweet reveals that FreeScout up to v1.8.208 is vulnerable to a stored XSS flaw (CVE-2026-32754), with no PoC, exploit code, patch, or evidence of active use provided.

    0001055
    137 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-32754 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.208 and below are vulnerable to Stored Cross-Site Scripting (XSS) thro… https://www.cve.org/CVERecord?id=CVE-2026-32754 ----- Traducción: CVE-2026-32754 Fre… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-32754 as a stored XSS vulnerability affecting FreeScout versions 1.8.208 and earlier, linking to the CVE record but providing no PoC, exploit, or patch information.

    0000037
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32754 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.208 and below are vulnerable to Stored Cross-Site Scripting (XSS) thro… https://www.cve.org/CVERecord?id=CVE-2026-32754

    Post summary

    The post announces CVE‑2026‑32754, identifying stored XSS in FreeScout versions 1.8.208 and earlier, but does not provide PoC, exploit code, or patch details.

    00000190
    56.8K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-32754: CRITICAL] Attention! FreeScout versions 1.8.208 and below are susceptible to Stored Cross-Site Scripting (XSS) attacks. Ensure your system is updated to version 1.8.209 to fix this vulnerabi...#cve,CVE-2026-32754,#cybersecurity https://cvefind.com/CVE-2026-32754

    Post summary

    The advisory warns that FreeScout versions 1.8.208 and earlier have a stored XSS flaw (CVE‑2026‑32754) and recommends upgrading to 1.8.209 to remediate it.

    0000040
    603 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32754: FreeScout: Stored XSS via Unesca... Raw Blade syntax {!! !!} turns every incoming email into a potential weaponized payload—attackers just hit send and wat... https://zerodaysignal.com/vulnerability/CVE-2026-32754 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces a stored XSS vulnerability in FreeScout via raw Blade syntax, noting that attackers can weaponize emails, but it does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    0000063
    154 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfreescoutfreescout---

Explore more