beefree.io SDK is vulnerable to Stored XSS in Social Media icon URL parameter in email builder functionality. Malicious attacker can inject arbitrary HTML and JS into template, which will be rendered/executed when visiting preview page. However due to beefree's Content Security Policy not all payloads will execute successfully.
This issue has been fixed in version 3.47.0.
Metrics
Affected Vendors & Products
References
History
Wed, 18 Mar 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | beefree.io SDK is vulnerable to Stored XSS in Social Media icon URL parameter in email builder functionality. Malicious attacker can inject arbitrary HTML and JS into template, which will be rendered/executed when visiting preview page. However due to beefree's Content Security Policy not all payloads will execute successfully. This issue has been fixed in version 3.47.0. | |
| Title | Stored XSS in beefree.io | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-03-18T11:03:59.900Z
Reserved: 2025-10-30T15:47:42.770Z
Link: CVE-2025-12518
No data.
Status : Received
Published: 2026-03-18T11:16:14.530
Modified: 2026-03-18T11:16:14.530
Link: CVE-2025-12518
No data.
OpenCVE Enrichment
No data.