← All reports

FreeScout versions prior to 1.8.213 are vulnerable to a stored cross-site scripting (XSS) vulnerability in the mailbox signature feature.

CybersecurityTechnologyConflictApr 21, 2026score 0.172 posts · 0 replies across 1 instances
The thread discusses two critical security vulnerabilities in the FreeScout software, specifically a stored cross-site scripting (XSS) vulnerability and a mass assignment vulnerability affecting versions prior to 1.8.213. These vulnerabilities pose significant security risks to users of the software, highlighting the need for timely patches and updates.

Claims

FreeScout versions prior to 1.8.213 are vulnerable to a stored cross-site scripting (XSS) vulnerability in the mailbox signature feature.
Parent: CybersecurityEntity: FreeScoutImpact: negativeDate: Apr 21, 2026Target: FreeScout versions prior to 1.8.213 are vulnerable to a stored cross-site scripting (XSS) vulnerability in the mailbox signature feature.
FreeScout versions prior to 1.8.213 are vulnerable to a mass assignment vulnerability in the mailbox connection settings endpoints.
Parent: CybersecurityEntity: FreeScoutImpact: negativeDate: Apr 21, 2026Target: FreeScout versions prior to 1.8.213 are vulnerable to a mass assignment vulnerability in the mailbox connection settings endpoints.

Source posts

@[email protected]
🟠 CVE-2026-40568 - High (8.5) FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a stored cross-site scripting (XSS) vulnerability in the mailbox signature feature. The sanitization function `Helper::stripDangerousTags()` (`app/Misc/He... 🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-40568/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
0 boosts · 0 favs · 0 replies · Apr 21, 2026
#cve#vulnerability#infosec#cybersecurity#security#tenda
@[email protected]
🔴 CVE-2026-40569 - Critical (9) FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a mass assignment vulnerability in the mailbox connection settings endpoints of FreeScout (`connectionIncomingSave()` at `app/Http/Controllers/MailboxesCo... 🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-40569/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
1 boosts · 0 favs · 0 replies · Apr 21, 2026
#cve#vulnerability#infosec#cybersecurity#security#tenda