Stored Cross-Site Scripting Vulnerability in Mettle SendPortal
CVE-2026-26483
6.1MEDIUM
What is CVE-2026-26483?
Mettle SendPortal versions 3.0.1 and earlier are vulnerable to a stored cross-site scripting (XSS) flaw due to inadequate sanitization of user-provided input within the template management feature. When a user submits data through the /templates endpoint, malicious JavaScript can be injected if not properly filtered. This injected script can execute in the browsers of users accessing the compromised templates, potentially leading to session hijacking, data theft, or other malicious actions.
