All verified exploits

CVE-2026-32754 Stored XSS in Email Notification Templates

Deterministic high FreeScout Added cve-verified-cve-2026-32754

Detects FreeScout instances running version 1.8.208 or earlier where incoming email bodies are rendered in agent notification emails without sanitization. Attackers can send crafted emails to any FreeScout-monitored inbox to inject JavaScript that executes when agents view the notification, enabling session hijacking and account takeover.

Is your app exploitable through CVE-2026-32754?

Scan your domain free