CVE-2026-26483

Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template management functionality. The application fails to properly sanitize user-supplied input in the content parameter of the /templates endpoint, allowing an attacker to persistently inject malicious JavaScript code that is executed in the browsers of users who access the affected template.
Configurations

No configuration.

History

20 Jul 2026, 19:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-79

20 Jul 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-20 18:16

Updated : 2026-07-20 19:17


NVD link : CVE-2026-26483

Mitre link : CVE-2026-26483

CVE.ORG link : CVE-2026-26483


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')