Stored XSS vulnerability (CVE-2025-12518) in Bee Content Design Befree SDK email builder…
Stored XSS vulnerability (CVE-2025-12518) in Bee Content Design Befree SDK email builder allows attackers to inject HTML/JS into templates, fixed in version 3.47.0.
CERT Polska coordinated disclosure of CVE-2025-12518, a stored cross-site scripting vulnerability in the Bee Content Design Befree SDK. The vulnerability exists in the social media icon URL parameter within the email builder functionality, allowing malicious actors to inject arbitrary HTML and JavaScript code into email templates. When victims view the preview page, the injected payload is rendered and executed in their browser context.
The impact is partially mitigated by Befree's Content Security Policy, which prevents certain payloads from executing successfully. However, the vulnerability still represents a viable attack vector for social engineering, credential harvesting, or session hijacking depending on CSP bypass techniques. The vendor has addressed the issue in version 3.47.0.
Organizations using Bee Content Design Befree SDK in their email marketing or content creation workflows should prioritize upgrading to the patched version. The vulnerability was responsibly disclosed by security researcher Michał Błaszczak through CERT Polska's coordinated vulnerability disclosure program.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/03/CVE-2025-12518
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free