🔐 CVE Alert

CVE-2026-75872

UNKNOWN 0.0

HTML Injection in MailerUp double opt-in verification email

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the first_name field of the subscription request, which is interpolated unescaped into the double opt-in verification email.

CWE CWE-80
Vendor maalfer
Product mailerup
Published Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for maalfer mailerup

Be the first to know when new unknown vulnerabilities affecting maalfer mailerup are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

maalfer / MailerUp
0 < 1.1.3

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/maalfer/mailerup/commit/da4aedc9621911df4ce0cc8f0b321dd6d10f40a5 github.com: https://github.com/maalfer/mailerup/releases/tag/v1.1.3 secur0.com: https://secur0.com/en/cna/cve-list/cve-2026-75872-html-injection-in-mailerup-double-optin-verification-email

Credits

Nacho García Egea Xoán M. Otero Jorge Secur0 CNA Mario Álvarez Fernández