highCVSS 7.2Vulnerability

CVE-2026-44742

Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.

Properties

summary
Postorius is vulnerable to XSS
severity
high
epss_score
0.00237
cvss_score
7.2
ghsa_published
2026-05-07T21:30:29Z
source_url
https://github.com/advisories/GHSA-r7c9-7pjq-hmm8
ghsa_updated
2026-05-12T16:20:38Z
ghsa_id
GHSA-r7c9-7pjq-hmm8
cve_id
CVE-2026-44742
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
is_ghsa_only
false
epss_percentile
0.14717

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/postorius

AFFECTS (1)

[Software]pip/postorius

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-44742 (CVSS 7.2) — Ninja Signal Threat Intelligence | Ninja Signal