#VU125918 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in EspoCRM - CVE-2026-33657
Published: April 14, 2026
EspoCRM
EspoCRM
Description
The vulnerability allows a remote user to inject arbitrary HTML into system-generated email notifications.
The vulnerability exists due to improper neutralization of HTML content in email notification templates when rendering Markdown-derived stream note content. A remote user can submit a specially crafted stream note to inject arbitrary HTML into system-generated email notifications.
User interaction is required to open the email notification, and the @mention feature enables targeted delivery to specific users.