Clevertap is a customer engagement and analytics platform whose vulnerability footprint centers on its web SDK and core platform, with the recurrent signal concentrated in application-layer input handling and dependency-management issues such as cross-site scripting, untrusted code inclusion, and origin validation errors. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Clevertap over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-26862HIGH CleverTap Web SDK version 1.15.2 and earlier is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage in the Visual Builder module. The origin validation in src | Feb 27, 2026 | 8.3 | 29 | NO | NO |
CVE-2026-26861HIGH CleverTap Web SDK version 1.15.2 and earlier is vulnerable to Cross-Site Scripting (XSS) via window.postMessage. The handleCustomHtmlPreviewPostMessageEvent function in src/util/ca | Feb 27, 2026 | 8.3 | 27 | NO | NO |
CVE-2023-2507MEDIUM CleverTap Cordova Plugin version 2.6.2 allows a remote attacker to execute JavaScript code in any application that is opened via a specially constructed deeplink by an attacker.
T | Jul 15, 2023 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Clevertap.
Media articles that mention a CVE ID that affects a product developed by Clevertap — matched by CVE ID, not by vendor name.