๐Ÿ” CVE Alert

CVE-2026-44742

HIGH 7.2
CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th

Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.

CWE CWE-79
Vendor postorius project
Product postorius
Published May 7, 2026
Last Updated May 7, 2026
Stay Ahead of the Next One

Get instant alerts for postorius project postorius

Be the first to know when new high vulnerabilities affecting postorius project postorius are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Postorius project / Postorius
0 โ‰ค 1.3.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
gitlab.com: https://gitlab.com/mailman/postorius/-/commit/c4706abd05ba6bcf472fc674b160d3a9d6a4868b gitlab.com: https://gitlab.com/mailman/postorius/-/merge_requests/972 gitlab.com: https://gitlab.com/mailman/postorius/-/issues/620 openwall.com: https://www.openwall.com/lists/oss-security/2026/05/07/3