CVE-2026-44742

Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May...

Basic Information

CVE State
PUBLISHED
Reserved Date
May 07, 2026
Published Date
May 07, 2026
Last Updated
May 25, 2026
Vendor
Postorius project
Product
Postorius
Description
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.

CVSS Scores

CVSS v3.1

7.2 - HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

SSVC Information

Exploitation
none
Automatable
Yes
Technical Impact
partial

Exploit Status

Exploited in the Wild
Yes (2026-06-01 13:26:33 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2026-06-01 13:26:33 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel