Количество 4
Количество 4
CVE-2025-59526
No description is available for this CVE.
CVE-2025-59526
mailgen is a Node.js package that generates responsive HTML e-mails for sending transactional mail. Prior to version 2.0.30, there is an HTML injection vulnerability in plaintext e-mails generated by Mailgen. Projects are affected if the Mailgen.generatePlaintext(email) method is used and given user-generated content. This vulnerability has been patched in version 2.0.30. A workaround involves stripping all HTML tags before passing any content into Mailgen.generatePlaintext(email).
GHSA-j2xj-h7w5-r7vp
Mailgen: HTML injection vulnerability in plaintext e-mails
BDU:2025-16482
Уязвимость метода Mailgen.generatePlaintext(email) пакета Mailgen программной платформы Node.js, позволяющая нарушителю выполнить произвольный HTML-код
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-59526 No description is available for this CVE. | 0% Низкий | 4 месяца назад | ||
CVE-2025-59526 mailgen is a Node.js package that generates responsive HTML e-mails for sending transactional mail. Prior to version 2.0.30, there is an HTML injection vulnerability in plaintext e-mails generated by Mailgen. Projects are affected if the Mailgen.generatePlaintext(email) method is used and given user-generated content. This vulnerability has been patched in version 2.0.30. A workaround involves stripping all HTML tags before passing any content into Mailgen.generatePlaintext(email). | 0% Низкий | 4 месяца назад | ||
GHSA-j2xj-h7w5-r7vp Mailgen: HTML injection vulnerability in plaintext e-mails | CVSS3: 5.3 | 0% Низкий | 4 месяца назад | |
BDU:2025-16482 Уязвимость метода Mailgen.generatePlaintext(email) пакета Mailgen программной платформы Node.js, позволяющая нарушителю выполнить произвольный HTML-код | CVSS3: 5.3 | 0% Низкий | 5 месяцев назад |
Уязвимостей на страницу