CVE-2026-64828
MEDIUMFroiden TableTrack 1.3.10 Stored XSS via Order Notes Field
Title source: cnaDescription
Froiden TableTrack through 1.3.10 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary HTML and JavaScript through the order notes field without sanitization. Attackers can craft malicious payloads in customer order placement that execute in the admin's browser session when viewing order details, enabling session token theft or unauthorized administrative actions.
References (3)
Core 3
Core References
Exploit technical-description
exploit
Researcher Disclosure
https://github.com/aaronamran/CVE-Disclosures/tree/main/CVE-2026/CVE-2026-64828
Product product
Project Webpage
https://codecanyon.net/item/tabletrack-the-complete-saas-restaurant-management-solution/55116396
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/froiden-tabletrack-stored-xss-via-order-notes-field
Scores
CVSS v3
6.1
EPSS
0.0020
EPSS Percentile
10.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (1)
Froiden/TableTrack
< 1.3.10
Published
Jul 22, 2026
Tracked Since
Jul 22, 2026