Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 1.3.13CPE match | cpe:2.3:a:postorius_project:postorius:*:*:*:*:*:*:*:* | ||
<= 1.3.13CPE matchmatch criteria | cpe:2.3:a:postorius_project:postorius:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.