Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/useplunk/plunk

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, a stored cross-site scripting (XSS) vulnerability exists in the campaign management feature, where the email body content created by authenticated project members is stored and later rendered in the admin dashboard using React's dangerouslySetInnerHTML without any HTML sanitization. This allows a lower-privileged member to embed malicious scripts in a campaign's email body that execute in the context of any admin or other member who views the campaign, potentially enabling session hijacking or unauthorized actions on their behalf. This issue has been patched in version 0.9.0.

Join the discussion

Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, the /webhooks/sns endpoint accepts Amazon SNS notification payloads from unauthenticated requests without verifying the SNS signature, certificate, or topic ARN, meaning anyone can forge a valid-looking webhook request. This allows an unauthenticated attacker to spoof SNS events to trigger workflow automations, unsubscribe contacts, manipulate email delivery metrics, and potentially exhaust billing credits. This issue has been patched in version 0.9.0.

Join the discussion

CVE-2026-34975 is a high-severity CRLF injection vulnerability in the open-source email platform plunk (useplunk) versions prior to 0.8.0. The flaw allows authenticated API users to inject arbitrary email headers by embedding carriage return and line feed characters in certain user-supplied fields such as from.name, subject, custom header keys/values, and attachment filenames. This can lead to silent email forwarding, reply redirection, or sender spoofing. The vulnerability is fixed in version 0.8.0 by adding input validation to reject these characters in the affected fields. The platform is cloud-hosted, and the vendor manages remediation for the service.

Join the discussion

CVE-2026-32096 is a critical Server-Side Request Forgery (SSRF) vulnerability affecting versions of the open-source email platform Plunk prior to 0.7.0. The flaw exists in the SNS webhook handler, allowing unauthenticated attackers to craft requests that force the server to perform arbitrary HTTP GET requests to any reachable host. This can lead to significant confidentiality breaches as attackers may access internal resources or sensitive data. The vulnerability has a CVSS score of 9.3, reflecting its high impact and ease of exploitation without authentication or user interaction. Although no known exploits are currently reported in the wild, organizations using affected versions should urgently upgrade to Plunk 0.7.0 or later.

Join the discussion

CVE-2026-32095 is a stored cross-site scripting (XSS) vulnerability in the open-source email platform Plunk, versions prior to 0.7.1. The issue arises because Plunk's image upload endpoint accepted SVG files, which can contain embedded JavaScript and be treated as active documents by browsers. This improper input neutralization allows attackers to inject malicious scripts that execute in the context of users' browsers, potentially compromising confidentiality and integrity. Exploitation requires low privileges and some user interaction, but no known active exploits have been reported. The vulnerability has a CVSS score of 5.4, indicating medium severity. Organizations using affected versions should upgrade to 0.7.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:github/useplunk/plunk
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses