CVE-2026-8255Disclosure

LOWCVSS 1.9 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A weakness has been identified in Devs Palace ERP Online up to 4.0.0. This affects an unknown part of the file /inventory/add_new_customer. This manipulation causes cross site scripting. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-11: 2Technical Details · 2026-05-11: 205-11
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-8255 A weakness has been identified in Devs Palace ERP Online up to 4.0.0. This affects an unknown part of the file /inventory/add_new_customer. This manipulation causes cro… https://www.cve.org/CVERecord?id=CVE-2026-8255

    Post summary

    A weakness in Devs Palace ERP Online v4.0.0 was disclosed, affecting an unspecified part of the file /inventory/add_new_customer, with no exploit details or patch information provided.

    00000140
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8255 Cross-Site Scripting Vulnerability in Devs Palace ERP Online Up To 4.0.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8255

    Post summary

    CVE-2026-8255, a cross‑site scripting vulnerability affecting Devs Palace ERP Online up to version 4.0.0, has been disclosed.

    0000053
    4.0K followersView on X

Explore more