Home Embedded Vulns General Vulns

CVE-2026-32095

MEDIUM 5.4

Our Analysis: esv

Our model has classified this vulnerability as relevant to esv Systems, helping your team prioritize efforts effectively.

Published Date March 11, 2026
Last Modified March 11, 2026
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Description

Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.1, Plunk's image upload endpoint accepted SVG files, which browsers treat as active documents capable of executing embedded JavaScript, creating a stored XSS vulnerability. This vulnerability is fixed in 0.7.1.

Potentially Affected Vendors