PT-2026-39195 · Plunk · Plunk
Bigbluewhale111
·
Published
2026-05-08
·
Updated
2026-05-09
·
CVE-2026-42192
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Plunk versions prior to 0.9.0
Description
A stored cross-site scripting (XSS) issue exists in the campaign management feature. Authenticated project members can embed malicious scripts in a campaign's email body, which are stored and subsequently rendered in the admin dashboard using React's
dangerouslySetInnerHTML without HTML sanitization. This allows a lower-privileged member to execute scripts in the context of an admin or other member viewing the campaign, potentially leading to session hijacking or unauthorized actions.Recommendations
Update to version 0.9.0.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plunk