CVE-2026-26460
Summary
| CVE | CVE-2026-26460 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-04-13 21:16:24 UTC |
| Updated | 2026-04-13 21:16:24 UTC |
| Description | A HTML Injection vulnerability exists in the Dashboard module of Vtiger CRM 8.4.0. The application fails to properly neutralize user-supplied input in the tabid parameter of the DashBoardTab view (getTabContents action), allowing an attacker to inject arbitrary HTML content into the dashboard interface. The injected content is rendered in the victim's browser |
Risk And Classification
Problem Types: n/a
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.simonjuguna.com/cve-2026-26460-html-injection-vulnerability-in-vtiger-open-so... | [email protected] | www.simonjuguna.com | |
| www.vtiger.com/open-source-crm | [email protected] | www.vtiger.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.