VYPR

Sendportal

by Mettle

Source repositories

CVEs (5)

  • CVE-2026-7145MedApr 27, 2026
    risk 0.35cvss 5.4epss 0.00

    A weakness has been identified in mettle sendportal up to 3.0.1. Affected is the function destroy of the file app/Http/Controllers/Workspaces/WorkspaceInvitationsController.php of the component Invitation Handler. This manipulation of the argument invitation causes authorization…

  • CVE-2026-10234LowJun 1, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was detected in Mettle sendportal up to 3.0.1. This affects an unknown part of the file /webview/ of the component Campaign Handler. The manipulation of the argument content results in cross site scripting. The attack can be launched remotely. The exploit is now…

  • CVE-2026-26483MedJul 20, 2026
    risk 0.00cvss 6.1epss 0.00

    Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template management functionality. The application fails to properly sanitize user-supplied input in the content parameter of the /templates endpoint, allowing an attacker to…

  • CVE-2026-15192MedJul 9, 2026
    risk 0.00cvss 6.5epss 0.01

    A vulnerability has been found in mettle sendportal up to 3.0.1. This issue affects the function sendgrid/postmark/postal/mailjet of the component APIv1 Webhooks. The manipulation leads to missing authentication. The attack is possible to be carried out remotely. The exploit has…

  • CVE-2026-15191MedJul 9, 2026
    risk 0.00cvss 6.3epss 0.00

    A flaw has been found in mettle sendportal up to 3.0.1. This vulnerability affects unknown code of the file vendor/mettle/sendportal-core/src/Http/Requests/CampaignStoreRequest.php of the component Campaign Creation Endpoint. Executing a manipulation can lead to authorization…