CVE-2026-41904Disclosure

LOWCVSS 7.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user with updateAutoReply permission can store an XSS payload in the mailbox auto-reply message. The payload is rendered unescaped in the auto-reply email sent to every customer who contacts the mailbox. Email clients do not enforce CSP, so the payload executes in the customer's webmail / mail-client context. This issue has been patched in version 1.8.217.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-05-07); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-07: 3Mentions · 2026-05-08: 1Technical Details · 2026-05-07: 3Technical Details · 2026-05-08: 105-0705-08
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-073
Disclosure2General1
2026-05-081
Disclosure1
Full discourse4 posts
  • Kaitan ID Security@KaitanSecurity
    General

    ⚠️ HIGH — CVE-2026-41904 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user wit… CVSS 7.6 Full analysis → https://sec.kaitan.id/cves/CVE-2026-41904 #HP #CyberSecurity #InfoSec

    Post summary

    The text announces CVE‑2026‑41904 with a CVSS score and affected version, but lacks specific exploit details, PoC, or patch information.

    0001051
    515 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41904 Stored Cross-Site Scripting in FreeScout Auto-Reply Messages Prior to 1.8.217 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41904

    Post summary

    CVE-2026-41904 is a stored XSS vulnerability in FreeScout Auto‑Reply messages prior to version 1.8.217; no proof of exploitation or patch information is provided.

    00000118
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-41904 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user with updateAutoReply permission can store an XSS p… https://www.cve.org/CVERecord?id=CVE-2026-41904 ----- Traducción: CVE-2026-41904 Fre… http://infoflow.cloud`

    Post summary

    CVE‑2026‑41904 discloses a stored XSS flaw in FreeScout before v1.8.217, whereby a user with "updateAutoReply" permission can store malicious JavaScript.

    0000037
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41904 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user with updateAutoReply permission can store an XSS p… https://www.cve.org/CVERecord?id=CVE-2026-41904

    Post summary

    The post discloses an XSS vulnerability in FreeScout versions before 1.8.217 that can be stored by users with updateAutoReply permission, with no mention of exploitation, PoC, or patch.

    00000212
    57.4K followersView on X

Explore more