Описание
Postorius is vulnerable to XSS
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.
Ссылки
Пакеты
Наименование
postorius
pip
Затронутые версииВерсия исправления
<= 1.3.13
Отсутствует
Связанные уязвимости
CVSS3: 7.2
ubuntu
3 месяца назад
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.
CVSS3: 7.2
nvd
3 месяца назад
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.
CVSS3: 7.2
debian
3 месяца назад
Postorius through 1.3.13 does not escape HTML in the message subject w ...