# Stored XSS vulnerability (CVE-2025-12518) in Bee Content Design Befree SDK email builder…

Published: 2026-03-18 · Severity: medium
Canonical: https://vorant.io/reports/d5957807-d9f1-4300-8f03-4a31c72d92a4/stored-xss-vulnerability-cve-2025-12518-in-bee-content-design-befree-sdk-email

> Stored XSS vulnerability (CVE-2025-12518) in Bee Content Design Befree SDK email builder allows attackers to inject HTML/JS into templates, fixed in version 3.47.0.

CERT Polska coordinated disclosure of CVE-2025-12518, a stored cross-site scripting vulnerability in the Bee Content Design Befree SDK. The vulnerability exists in the social media icon URL parameter within the email builder functionality, allowing malicious actors to inject arbitrary HTML and JavaScript code into email templates. When victims view the preview page, the injected payload is rendered and executed in their browser context.

The impact is partially mitigated by Befree's Content Security Policy, which prevents certain payloads from executing successfully. However, the vulnerability still represents a viable attack vector for social engineering, credential harvesting, or session hijacking depending on CSP bypass techniques. The vendor has addressed the issue in version 3.47.0.

Organizations using Bee Content Design Befree SDK in their email marketing or content creation workflows should prioritize upgrading to the patched version. The vulnerability was responsibly disclosed by security researcher Michał Błaszczak through CERT Polska's coordinated vulnerability disclosure program.

## Mentioned in this report

- Vulnerabilities: CVE-2025-12518

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2025-12518

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d5957807-d9f1-4300-8f03-4a31c72d92a4/stored-xss-vulnerability-cve-2025-12518-in-bee-content-design-befree-sdk-email.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
