PatchSiren

Devs Palace CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Devs Palace CVE published 2026-05-11

CVE-2026-8262

A vulnerability was identified in Devs Palace ERP Online up to 4.0.0. This impacts an unknown function of the file /accounts/chart-save. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit is publicly available and might be used. The vulnerability class is cross-site scripting, which can lead to unauthorized actions on behalf of the user. The affected prod [truncated]

LOW Devs Palace CVE published 2026-05-11

CVE-2026-8256

A cross-site scripting vulnerability has been detected in Devs Palace ERP Online up to 4.0.0. The vulnerability affects unknown code of the file /accounts/mr-save, leading to cross-site scripting. The attack can be launched remotely. The exploit has been disclosed publicly. Users should review their deployments for affected versions and consider applying patches or mitigations.

LOW Devs Palace CVE published 2026-05-11

CVE-2026-8255

A weakness has been identified in Devs Palace ERP Online up to 4.0.0. This affects an unknown part of the file /inventory/add_new_customer. The manipulation causes cross site scripting. The attack can be initiated remotely. This vulnerability has a CVSS score of 1.9 and is considered Low severity. Users of Devs Palace ERP Online up to 4.0.0 should be aware of this cross site scripting vulnerability and ta [truncated]

LOW Devs Palace CVE published 2026-05-11

CVE-2026-8254

A security flaw has been discovered in Devs Palace ERP Online up to 4.0.0. Affected by this issue is some unknown functionality of the file /inventory/sales_save. The manipulation results in cross site scripting. It is possible to launch the attack remotely. This vulnerability has a CVSS score of 1.9 and is considered Low severity. Users of Devs Palace ERP Online up to version 4.0.0 should assess the risk [truncated]

LOW Devs Palace CVE published 2026-05-11

CVE-2026-8253

A vulnerability was identified in Devs Palace ERP Online up to 4.0.0, affecting an unknown functionality of the file /inventory/purchase_save, which allows for cross site scripting attacks that can be initiated remotely. The exploit is publicly available and might be used. Users should assess the risk and review vendor remediation. Limited details are available on the affected scope and vendor response.

LOW Devs Palace CVE published 2026-05-10

CVE-2026-8221

CVE-2026-8221 is a remote cross-site scripting issue reported in Devs Palace ERP Online up to 4.0.0, affecting the /inventory/item-save path. The NVD record also cites public proof-of-concept references, so affected organizations should treat the issue as publicly documented even though the scored impact is low.

LOW Devs Palace CVE published 2026-05-10

CVE-2026-8220

CVE-2026-8220 describes a remote cross-site scripting issue in Devs Palace ERP Online up to 4.0.0, affecting an unknown function under /inventory/customer-save. The source corpus says the exploit is public, which raises practical risk even though the listed CVSS score is low (1.9). The NVD record also maps the issue to CWE-79 and CWE-94, and the vector indicates network access with user interaction and hi [truncated]

LOW Devs Palace CVE published 2026-05-10

CVE-2026-8219

CVE-2026-8219 was published on 2026-05-10 and describes a cross-site scripting issue affecting Devs Palace ERP Online up to 4.0.0, specifically in an unknown function of /inventory/supplier-save. The record indicates remote exploitation is possible and that a public proof-of-concept reference exists. Although the CVSS score is low (1.9), the NVD vector shows the attack requires high privileges and user in [truncated]

LOW Devs Palace CVE published 2026-05-10

CVE-2026-8218

CVE-2026-8218 describes a remotely launchable cross-site scripting issue affecting Devs Palace ERP Online up to version 4.0.0, with the affected area identified as /inventory/purchase_return_save. The NVD record rates the issue LOW and cites public reference material, including a PoC image and VulDB submissions. The source description also states that the vendor was contacted early and did not respond.