beefree.io SDK is vulnerable to Stored XSS in Social Media icon URL parameter in email builder functionality. Malicious attacker can inject arbitrary HTML and JS into template, which will be rendered/executed when visiting preview page. However due to beefree's Content Security Policy not all payloads will execute successfully.
This issue has been fixed in version 3.47.0.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Mar 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bee Content Design
Bee Content Design befree Sdk |
|
| Vendors & Products |
Bee Content Design
Bee Content Design befree Sdk |
Wed, 18 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Mar 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | beefree.io SDK is vulnerable to Stored XSS in Social Media icon URL parameter in email builder functionality. Malicious attacker can inject arbitrary HTML and JS into template, which will be rendered/executed when visiting preview page. However due to beefree's Content Security Policy not all payloads will execute successfully. This issue has been fixed in version 3.47.0. | |
| Title | Stored XSS in beefree.io | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published: 2026-03-18T11:03:28.176Z
Updated: 2026-03-18T14:21:26.302Z
Reserved: 2025-10-30T15:47:42.770Z
Link: CVE-2025-12518
Updated: 2026-03-18T14:21:12.265Z
Status : Awaiting Analysis
Published: 2026-03-18T11:16:14.530
Modified: 2026-03-18T14:52:44.227
Link: CVE-2025-12518
No data.