MEDIUM 6.9 NVD
CVE-2026-75872
HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message c
HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the first_name field of the subscription request, which is interpolated unescaped into the double opt-in verification email.
References
- https://github.com/maalfer/mailerup/commit/da4aedc9621911df4ce0cc8f0b321dd6d10f40a5
- https://github.com/maalfer/mailerup/releases/tag/v1.1.3
- https://secur0.com/en/cna/cve-list/cve-2026-75872-html-injection-in-mailerup-double-optin-
This medium severity vulnerability with a CVSS score of 6.9 was published on 2026-08-18 via NVD.
vulnfeed aggregates 11140 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.