MEDIUM
CleverTap
CVE published 2026-07-30
CVE-2025-51684
CVE-2025-51684 is a Cross Site Scripting (XSS) vulnerability in CleverTap Web SDK v1.15.1. The application fails to sanitize untrusted data received via window.postMessage before injecting it into the page DOM, allowing an attacker to execute arbitrary JavaScript in the context of the hosting site. This vulnerability can lead to potential execution of arbitrary JavaScript, compromising user sessions or se [truncated]