Описание
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| postorius | unfixed | package |
Примечания
https://gitlab.com/mailman/postorius/-/commit/8d00a3c317729f37435bdbd27170f630e341f29e
https://gitlab.com/mailman/postorius/-/merge_requests/972
EPSS
Процентиль: 15%
0.00237
Низкий
Связанные уязвимости
CVSS3: 7.2
ubuntu
3 месяца назад
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.
CVSS3: 7.2
nvd
3 месяца назад
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.
EPSS
Процентиль: 15%
0.00237
Низкий