CVE-2026-54216
TeamDavid: Reflected Cross Site Scripting (XSS) via the 'EntryInfo' parameter
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS) vulnerability. By sending a specially crafted link including an arbitrary path, an XSS payload or the parameter “EntryInfo”, and the parameter “!templateName=entryMail”, an attacker can cause the payload to execute in the victim’s browser when they click the link. This issue affects TeamDavid through Rollout 524.
| CWE | CWE-79 |
| Vendor | tobit laboratories ag |
| Product | teamdavid |
| Published | Aug 7, 2026 |
| Last Updated | Aug 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for tobit laboratories ag teamdavid
Be the first to know when new unknown vulnerabilities affecting tobit laboratories ag teamdavid are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Tobit Laboratories AG / TeamDavid
0 ≤ Rollout 524
References
Credits
Dario Weiss of InfoGuard Labs