Stored Cross-Site Scripting Vulnerability in Froiden TableTrack
CVE-2026-64828
Key Information:
- Vendor
Froiden
- Status
- Vendor
- CVE Published:
- 22 July 2026
Badges
What is CVE-2026-64828?
Froiden TableTrack versions up to 1.3.10 are susceptible to a stored cross-site scripting vulnerability through the order notes field. This flaw permits unauthenticated attackers to inject arbitrary HTML and JavaScript into the application, allowing for malicious payloads to execute within the admin's browser session when viewing order details. As a consequence, this vulnerability facilitates potential session token theft and the possibility of unauthorized administrative actions, thereby compromising the security of the application and its users.
Affected Version(s)
TableTrack 0 <= 1.3.10
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
