CVE-2026-8254Disclosure

LOWCVSS 1.9 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in Devs Palace ERP Online up to 4.0.0. Affected by this issue is some unknown functionality of the file /inventory/sales_save. The manipulation results in cross site scripting. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-11: 3Technical Details · 2026-05-11: 105-11
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-8254 A security flaw has been discovered in Devs Palace ERP Online up to 4.0.0. Affected by this issue is some unknown functionality of the file /inventory/sales_save. The m… https://www.cve.org/CVERecord?id=CVE-2026-8254 ----- Traducción: CVE-2026-8254 Se … http://infoflow.cloud`

    Post summary

    A short announcement of CVE-2026-8254, identifying Devs Palace ERP Online as affected, but lacking detailed technical information, exploitation evidence, or remediation steps.

    0000034
    77 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-8254 A security flaw has been discovered in Devs Palace ERP Online up to 4.0.0. Affected by this issue is some unknown functionality of the file /inventory/sales_save. The m… https://www.cve.org/CVERecord?id=CVE-2026-8254

    Post summary

    A vulnerability (CVE‑2026‑8254) was identified in Devs Palace ERP Online 4.0.0 affecting an unknown function in /inventory/sales_save, but the post contains no PoC, exploit, or patch information.

    00000196
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8254 Cross Site Scripting in Devs Palace ERP Online Up To 4.0.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8254

    Post summary

    CVE-2026-8254 describes a cross‑site scripting flaw in Devs Palace ERP Online versions up to 4.0.0, with detailed information available via the provided Vulmon link.

    0000046
    4.0K followersView on X

Explore more