CVE-2026-44742

Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.
Configurations

Configuration 1 (hide)

cpe:2.3:a:postorius_project:postorius:*:*:*:*:*:*:*:*

History

26 May 2026, 00:16

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2026/05/msg00045.html -
References () https://gitlab.com/mailman/postorius/-/issues/620 - Vendor Advisory, Issue Tracking () https://gitlab.com/mailman/postorius/-/issues/620 - Issue Tracking, Vendor Advisory

14 May 2026, 17:42

Type Values Removed Values Added
First Time Postorius Project
Postorius Project postorius
CPE cpe:2.3:a:postorius_project:postorius:*:*:*:*:*:*:*:*
References () https://gitlab.com/mailman/postorius/-/commit/c4706abd05ba6bcf472fc674b160d3a9d6a4868b - () https://gitlab.com/mailman/postorius/-/commit/c4706abd05ba6bcf472fc674b160d3a9d6a4868b - Patch
References () https://gitlab.com/mailman/postorius/-/issues/620 - () https://gitlab.com/mailman/postorius/-/issues/620 - Vendor Advisory, Issue Tracking
References () https://gitlab.com/mailman/postorius/-/merge_requests/972 - () https://gitlab.com/mailman/postorius/-/merge_requests/972 - Issue Tracking, Patch
References () https://www.openwall.com/lists/oss-security/2026/05/07/3 - () https://www.openwall.com/lists/oss-security/2026/05/07/3 - Mailing List, Patch, Third Party Advisory

07 May 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-07 19:16

Updated : 2026-05-26 00:16


NVD link : CVE-2026-44742

Mitre link : CVE-2026-44742

CVE.ORG link : CVE-2026-44742


JSON object : View

Products Affected

postorius_project

  • postorius
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')