
CVE-2025-12518 http://beefree.io SDK is vulnerable to Stored XSS in Social Media icon URL parameter in email builder functionality. Malicious attacker can inject arbitrary HTML and JS into… https://www.cve.org/CVERecord?id=CVE-2025-12518
Post summary
CVE‑2025‑12518 discloses a stored XSS issue in the Beefree SDK’s email builder, where the Social Media icon URL parameter can be used to inject arbitrary HTML and JavaScript.
