Stored XSS Fixed in Beefree SDK
A stored XSS vulnerability in Beefree SDK's email builder let attackers inject HTML/JS via the Social Media icon URL parameter, fixed in version 3.47.0.
CERT Polska coordinated disclosure of CVE-2025-12518, a stored cross-site scripting vulnerability in the Beefree SDK, a widely used email template builder. The flaw resides in the Social Media icon URL parameter within the email builder functionality, allowing an attacker to inject arbitrary HTML and JavaScript into an email template. This malicious payload would execute when a victim visits the template's preview page.
The vendor's Content Security Policy provides partial mitigation, limiting which payloads can successfully execute, which reduces the practical impact of the vulnerability. The issue has been resolved in Beefree SDK version 3.47.0. The vulnerability was responsibly reported by researcher Michał Błaszczak and coordinated through CERT Polska's standard disclosure process, with no indication of active exploitation in the wild.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/03/CVE-2025-12518
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free