CVE-2026-42192

MEDIUM

Plunk: Stored XSS in campaign view

Title source: cna
STIX 2.1

Description

Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, a stored cross-site scripting (XSS) vulnerability exists in the campaign management feature, where the email body content created by authenticated project members is stored and later rendered in the admin dashboard using React's dangerouslySetInnerHTML without any HTML sanitization. This allows a lower-privileged member to embed malicious scripts in a campaign's email body that execute in the context of any admin or other member who views the campaign, potentially enabling session hijacking or unauthorized actions on their behalf. This issue has been patched in version 0.9.0.

References (2)

Core 2
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/useplunk/plunk/releases/tag/v0.9.0

Scores

CVSS v3 5.4
EPSS 0.0018
EPSS Percentile 7.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
useplunk/plunk < 0.9.0
Published May 08, 2026
Tracked Since May 09, 2026