| CVE ID | CVE-2025-12518 |
| Publication date | 18 March 2026 |
| Vendor | Bee Content Design |
| Product | Befree SDK |
| Vulnerable versions | All before 3.47.0 |
| Vulnerability type (CWE) | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') (CWE-79) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Bee Content Design Befree SDK software and participated in coordination of its disclosure.
The vulnerability CVE-2025-12518: beefree.io SDK is vulnerable to Stored XSS in Social Media icon URL parameter in email builder functionality. Malicious attacker can inject arbitrary HTML and JS into template, which will be rendered/executed when visiting preview page. However due to beefree's Content Security Policy not all payloads will execute successfully.
This issue has been fixed in version 3.47.0.
Credits
We thank Michał Błaszczak for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.