# Stored XSS Fixed in Beefree SDK

Published: 2026-03-18 · Severity: low
Canonical: https://vorant.io/reports/b20eba07-5fc8-50c4-9e12-d3dd25ce8e87/stored-xss-fixed-in-beefree-sdk

> A stored XSS vulnerability in Beefree SDK's email builder let attackers inject HTML/JS via the Social Media icon URL parameter, fixed in version 3.47.0.

CERT Polska coordinated disclosure of CVE-2025-12518, a stored cross-site scripting vulnerability in the Beefree SDK, a widely used email template builder. The flaw resides in the Social Media icon URL parameter within the email builder functionality, allowing an attacker to inject arbitrary HTML and JavaScript into an email template. This malicious payload would execute when a victim visits the template's preview page.

The vendor's Content Security Policy provides partial mitigation, limiting which payloads can successfully execute, which reduces the practical impact of the vulnerability. The issue has been resolved in Beefree SDK version 3.47.0. The vulnerability was responsibly reported by researcher Michał Błaszczak and coordinated through CERT Polska's standard disclosure process, with no indication of active exploitation in the wild.

## Mentioned in this report

- Vulnerabilities: CVE-2025-12518

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2025-12518

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b20eba07-5fc8-50c4-9e12-d3dd25ce8e87/stored-xss-fixed-in-beefree-sdk.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
