Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-32754

30
FAUCET Score

CVE-2026-32754 is a critical Stored Cross-Site Scripting (XSS) vulnerability impacting FreeScout versions 1.8.208 and below. This flaw allows an unauthenticated attacker to inject malicious content into outgoing email notifications by sending a crafted email, as incoming email bodies are stored and rendered unescaped. Rated with a CVSS score of 9.3 (CRITICAL), successful exploitation, which requires user interaction, can lead to universal HTML injection for phishing or tracking, and potentially JavaScript execution for session hijacking or account takeover in vulnerable email clients. There is currently no evidence of active exploitation, public exploit code availability, or significant community discussion for this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.8.209CPE matchmatch criteria
cpe:2.3:a:freescout:freescout:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.3CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
5.8
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.53%
Probability of exploitation in next 30 days
EPSS Percentile
41.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0053 is in the 46th percentile among its peer group of 834 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / freescout-help-desk/freescout/commit/3329379db38a86cf7069b0709061b95a7d38985b
Patch
github.com / freescout-help-desk/freescout/releases/tag/1.8.209
ProductRelease Notes
github.com / freescout-help-desk/freescout/security/advisories/GHSA-56h2-5556-r6mg
ExploitMitigationVendor Advisory