<p align="center"> <img src="https://github.com/CleverTap/clevertap-ios-sdk/blob/master/docs/images/clevertap-logo.png" width = "50%"/> </p>
93%
Total Score
64
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-26861 clevertap-web-sdk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.15.3. | 0.0.0 - 1.15.3 | High |
CVE-2026-26862 clevertap-web-sdk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.15.3. | 0.0.0 - 1.15.3 | High |
AIKIDO-2025-10849 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. clevertap-web-sdk is vulnerable to Improper Input Validation in versions 1.0.0 - 2.3.1. | 1.0.0 - 2.3.1 | Medium |
AIKIDO-2025-10332 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. clevertap-web-sdk is vulnerable to Permissive Cross-domain Policy with Untrusted Domains in versions 1.14.2 - 1.15.2. | 1.14.2 - 1.15.2 | Low |
AIKIDO-2025-10320 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. clevertap-web-sdk is vulnerable to Cross-site Scripting (XSS) in versions 1.9.1 - 1.15.1. | 1.9.1 - 1.15.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
core-js Version ^3.49.0 | — | — |
crypto-js Version ^4.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant