PT-2026-66576 · Clevertap · Clevertap Web Sdk

CVE-2025-51684

·

Published

2026-07-30

·

Updated

2026-07-31

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CleverTap Web SDK version 1.15.1
Description Cross Site Scripting (XSS) occurs because the application fails to sanitize untrusted data received via window.postMessage before injecting it into the page DOM. An attacker can craft a malicious message that, when processed by the renderCustomHtml() function, leads to the execution of arbitrary JavaScript within the context of the hosting site.
Recommendations As a temporary workaround, restrict the use of the renderCustomHtml() function until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-51684

Affected Products

Clevertap Web Sdk