LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-32095

useplunk · plunk

Published
CVSS5.4
Severitymedium
WeaknessCWE-79
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Description

Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.1, Plunk's image upload endpoint accepted SVG files, which browsers treat as active documents capable of executing embedded JavaScript, creating a stored XSS vulnerability. This vulnerability is fixed in 0.7.1.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-32095

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-32095.