Postorius Project maintains a focused web-based management interface for the Mailman mailing-list platform, with a modestly scoped but strategically positioned vulnerability surface in mail-server administration tooling. The recurring signal centers on input-handling weaknesses, particularly cross-site scripting in web-page generation, which reflects the risks inherent to administrative web applications that process user-supplied mailing-list configuration and content. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Postorius Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-44742MEDIUM Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. | May 7, 2026 | 6.1 | 25 | NO | NO |
CVE-2021-40347MEDIUM An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) can send a crafted POST request to unsubscribe any user from a | Sep 10, 2021 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Postorius Project.
Media articles that mention a CVE ID that affects a product developed by Postorius Project — matched by CVE ID, not by vendor name.