Stored XSS Vulnerability in beefree.io SDK's Email Builder Functionality
CVE-2025-12518

5.3MEDIUM

Key Information:

Vendor
CVE Published:
18 March 2026

What is CVE-2025-12518?

The beefree.io SDK is susceptible to a Stored XSS vulnerability within the email builder functionality. This flaw allows an attacker to inject arbitrary HTML and JavaScript code through the Social Media icon URL parameter. When the email template is previewed, this malicious content can be rendered and executed. Due to beefree's Content Security Policy, not all injected payloads will be successful, but the potential for exploitation remains a significant security concern. The vulnerability has been addressed in version 3.47.0.

Affected Version(s)

Befree SDK 0 < 3.47.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michał Błaszczak
.