Mettle · Sendportal · CVE-2026-10234
**Name of the Vulnerable Software and Affected Versions**
Mettle sendportal versions prior to 3.0.2
**Description**
A cross site scripting issue exists in the Campaign Handler component within the `/webview/` file. A remote attacker can trigger this by manipulating the `content` argument. Cross site scripting is a technique where malicious scripts are injected into trusted websites.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.