Kaitan ID Security[verified]@KaitanSecurityGeneral
The text announces CVE‑2026‑41904 with a CVSS score and affected version, but lacks specific exploit details, PoC, or patch information.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
CVE-2026-41904 is a stored XSS vulnerability in FreeScout Auto‑Reply messages prior to version 1.8.217; no proof of exploitation or patch information is provided.
Infoflowcloud@infoflowcloudDisclosure
CVE‑2026‑41904 discloses a stored XSS flaw in FreeScout before v1.8.217, whereby a user with "updateAutoReply" permission can store malicious JavaScript.
CVE@CVEnewDisclosure
The post discloses an XSS vulnerability in FreeScout versions before 1.8.217 that can be stored by users with updateAutoReply permission, with no mention of exploitation, PoC, or patch.