Stored Cross-Site Scripting Vulnerability in Mettle SendPortal
CVE-2026-26483

6.1MEDIUM

Key Information:

Vendor

Mettle

Vendor
CVE Published:
20 July 2026

What is CVE-2026-26483?

Mettle SendPortal versions 3.0.1 and earlier are vulnerable to a stored cross-site scripting (XSS) flaw due to inadequate sanitization of user-provided input within the template management feature. When a user submits data through the /templates endpoint, malicious JavaScript can be injected if not properly filtered. This injected script can execute in the browsers of users accessing the compromised templates, potentially leading to session hijacking, data theft, or other malicious actions.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.