CleverTap Web SDK是CleverTap开源的一个开发者工具包。 CleverTap Web SDK 1.15.2及之前版本存在安全漏洞,该漏洞源于src/util/campaignRender/nativeDisplay.js中的handleCustomHtmlPreviewPostMessageEvent函数使用includes方法进行来源验证不足,可能导致跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-3292 | 6.3 MEDIUM | jizhiCMS Batch Model.php findAll sql injection |
| CVE-2026-3281 | 5.3 MEDIUM | libvips bandrank.c vips_bandrank_build heap-based overflow |
| CVE-2026-3284 | 3.3 LOW | libvips extract.c vips_extract_area_build integer overflow |
| CVE-2026-3283 | 3.3 LOW | libvips extract.c vips_extract_band_build out-of-bounds |
| CVE-2026-3282 | 3.3 LOW | libvips unpremultiply.c vips_unpremultiply_build out-of-bounds |
| CVE-2025-69437 | PublicCMS 安全漏洞 | |
| CVE-2026-26862 | CleverTap Web SDK 安全漏洞 |
No comments yet