Filtered by vendor Bee Content Design Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-12518 1 Bee Content Design 1 Befree Sdk 2026-03-19 N/A
beefree.io SDK is vulnerable to Stored XSS in Social Media icon URL parameter in email builder functionality. Malicious attacker can inject arbitrary HTML and JS into template, which will be rendered/executed when visiting preview page. However due to beefree's Content Security Policy not all payloads will execute successfully. This issue has been fixed in version 3.47.0.