CVE-2026-8218Disclosure

LOWCVSS 1.9 · LOW

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A weakness has been identified in Devs Palace ERP Online up to 4.0.0. The affected element is an unknown function of the file /inventory/purchase_return_save. Executing a manipulation can lead to cross site scripting. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-05-10: 4Technical Details · 2026-05-10: 205-10
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets5 URLs
Full discourse4 posts
  • OverResearched Intelligence@ORIntelligence
    General

    Devs Palace ERP CVE-2026-8218–8221 Vim heap RCE CVE-2026-45130 Lynx RaaS posts 8 victims FulcrumSec lists 7–12TB Avnet MacSync via http://Claude.ai chats Full brief: https://intel.overresearched.net/2026/05/10/cti-daily-brief/ #Daily #ThreatIntel #InfoSec

    Post summary

    The brief lists several CVE identifiers and a few related events but lacks detailed analysis, evidence of exploitation, or mitigation information.

    0000072
    7 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-8218 A weakness has been identified in Devs Palace ERP Online up to 4.0.0. The affected element is an unknown function of the file /inventory/purchase_return_save. Executing… https://www.cve.org/CVERecord?id=CVE-2026-8218 ----- Traducción: CVE-2026-8218 Se … http://infoflow.cloud`

    Post summary

    A weakness in Devs Palace ERP Online up to 4.0.0 affecting an unknown function in /inventory/purchase_return_save has been identified (CVE-2026-8218); no PoC, exploit, or patch information is provided.

    0000019
    76 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-8218 A weakness has been identified in Devs Palace ERP Online up to 4.0.0. The affected element is an unknown function of the file /inventory/purchase_return_save. Executing… https://www.cve.org/CVERecord?id=CVE-2026-8218

    Post summary

    A brief mention of CVE-2026-8218 for Devs Palace ERP Online with minimal detail; no evidence of PoC, exploit, patch, or technical specifics.

    00000127
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8218 Cross-Site Scripting in Devs Palace ERP Online Up to 4.0.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8218

    Post summary

    The text announces CVE-2026-8218, a cross‑site scripting flaw in Devs Palace ERP Online up to 4.0.0, but does not provide PoC, exploit, or patch information.

    0000051
    4.0K followersView on X

Explore more