SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-71368

MEDIUM · CVSS 6.1 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

F-RevoCRM is vulnerable to a cross-site scripting (XSS) flaw that can be exploited when a user views a specially crafted page while logged in. This vulnerability may allow attackers to execute unintended operations on behalf of the user, potentially compromising user data and session integrity. Organizations using F-RevoCRM should prioritize remediation to protect against potential exploitation.

CVE
CVE-2026-71368
Severity
MEDIUM
CVSS
6.1
EPSS
0.16%

Original NVD Description

F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operations may be performed.