LOWVulnerability
CVE-2026-75872
HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the first_name field of the subscription request, which is interpolated unescaped into the double opt-in verification email.
Properties
- epss_score
- 0.00709
- cve_id
- CVE-2026-75872
- published_at
- 2026-08-18T15:17:15.150
- last_modified
- 2026-09-01T20:52:27.110
- epss_percentile
- 0.51103
Related Entities (3)
ENRICHED_BY (1)
→[Source]FIRST EPSS
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (1)
→[Weakness]Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Explore deeper with Ninja Signal's threat intelligence graph