VORANT. Threat Intelligence Sign in Get the full feed

Stored XSS Fixed in Beefree SDK

low vulnerability

A stored XSS vulnerability in Beefree SDK's email builder let attackers inject HTML/JS via the Social Media icon URL parameter, fixed in version 3.47.0.

CERT Polska coordinated disclosure of CVE-2025-12518, a stored cross-site scripting vulnerability in the Beefree SDK, a widely used email template builder. The flaw resides in the Social Media icon URL parameter within the email builder functionality, allowing an attacker to inject arbitrary HTML and JavaScript into an email template. This malicious payload would execute when a victim visits the template's preview page.

The vendor's Content Security Policy provides partial mitigation, limiting which payloads can successfully execute, which reduces the practical impact of the vulnerability. The issue has been resolved in Beefree SDK version 3.47.0. The vulnerability was responsibly reported by researcher Michał Błaszczak and coordinated through CERT Polska's standard disclosure process, with no indication of active exploitation in the wild.

Mentioned in this report

Vulnerabilities CVE-2025-12518

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2025-12518

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free