Impact
A stored cross‑site scripting flaw in Bynder before 12 January 2026 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. Attackers can inject and store malicious scripts that are later delivered to users’ browsers, enabling client‑side code execution such as credential theft, defacement, or other web‑based attacks. The vulnerability is classified as CWE‑79.
Affected Systems
This flaw affects the Bynder web application prior to 12 January 2026. No other versions or vendors are listed. Users running any affected version before that date are at risk.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score of 0.00138 reflects a very low but non‑zero exploitation probability. The vulnerability was publicly disclosed, suggesting the risk of exploitation is non‑negligible. The issue is not yet catalogued in CISA’s KEV list; however, the stored nature of the payload means an attacker could trigger it via legitimate user interactions, making it potentially effective against unsuspecting users. The attack vector is inferred to be through the application’s content management interface, requiring user authentication and content delivery to the victim’s browser.
OpenCVE Enrichment