SecBoard
Zurück zur CVE-Übersicht

CVE-2026-44742

HIGH(7.2)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Risk Signal Score18/100 — NIEDRIG
  • CVSS 7.2 — Hoch

EPSS-Score

0%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

7.2

Technische Schwere

Beschreibung

Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.

GitHub Advisories

GHSA-r7c9-7pjq-hmm8HIGH

Postorius is vulnerable to XSS

pip/postorius
GitHub Advisory

Referenzen