Skip to main content

Vendor archive

clevertap CVEs

Beta · best-effort

3 CVEs tagged to vendor clevertap1 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-26862

Published Feb 27, 2026

CleverTap Web SDK version 1.15.2 and earlier is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage in the Visual Builder module. The origin validation in sr…

CVSS 8.3 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-26861

Published Feb 27, 2026

CleverTap Web SDK version 1.15.2 and earlier is vulnerable to Cross-Site Scripting (XSS) via window.postMessage. The handleCustomHtmlPreviewPostMessageEvent function in src/util/c…

CVSS 8.3 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2023-2507

Published Jul 15, 2023

CleverTap Cordova Plugin version 2.6.2 allows a remote attacker to execute JavaScript code in any application that is opened via a specially constructed deeplink by an attacker.…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1