CVE-2026-44742
EUVD-2026-2841507.05.2026, 19:16
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| postorius_project | postorius | 𝑥 ≤ 1.3.13 |
𝑥
= Vulnerable software versions
Debian Releases
References