CVE-2026-26483

Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template management functionality. The application fails to properly sanitize user-supplied input in the content parameter of the /templates endpoint, allowing an attacker to persistently inject malicious JavaScript code that is executed in the browsers of users who access the affected template.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-20 18:16

Updated : 2026-07-23 18:28


NVD link : CVE-2026-26483

Mitre link : CVE-2026-26483

CVE.ORG link : CVE-2026-26483


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')