Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Michał Błaszczak

#21546of 53,635
11.1Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-26052
5.3
2026-03-18
Unknown · Beefree.Io Sdk · CVE-2025-12518
**Name of the Vulnerable Software and Affected Versions** beefree.io SDK versions prior to 3.47.0 **Description** The beefree.io SDK contains a Stored Cross-Site Scripting (XSS) issue within the Social Media icon URL parameter of the email builder functionality. A malicious actor can inject arbitrary HTML and JavaScript into a template. This injected code will be rendered and executed when a user views the preview page. The effectiveness of payloads may be limited by the beefree Content Security Policy. **Recommendations** Update to version 3.47.0 or later.
PT-2020-16270
5.8
2020-12-28
Zammad · Zammad · CVE-2020-26033
**Name of the Vulnerable Software and Affected Versions** Zammad versions prior to 3.4.1 **Description** An issue was discovered in the Tag and Link REST API endpoints for add and delete operations, which lack a CSRF token check. The "Tag and Link REST API endpoints" are affected, specifically the endpoints for adding and deleting. **Recommendations** For versions prior to 3.4.1, update to version 3.4.1 or later to resolve the issue. As a temporary workaround, consider implementing a CSRF token check for the Tag and Link REST API endpoints until a patch is available.