CVE-2026-71368: Thinkingreed Inc F-Revocrm

Medium severity, CVSS 5.1. EPSS: 0.3% chance of exploitation in the next 30 days.

F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operations may be performed.

Affected products

Published 2026-08-20. Last modified 2026-08-28.