CVE-2026-75872
MEDIUM
6,9
Source: 4daa8cea-433a-44bd-9456-53b127fc289a
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the first_name field of the subscription request, which is interpolated unescaped into the double opt-in verification email.
80
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Availability
Potential Impacts:
Read Application Data
Execute Unauthorized Code Or Commands
Applicable Platforms
Technologies:
Web Based, Web Server
https://github.com/maalfer/mailerup/commit/da4aedc9621911df4ce0cc8f0b321dd6d10f…
https://github.com/maalfer/mailerup/releases/tag/v1.1.3
https://secur0.com/en/cna/cve-list/cve-2026-75872-html-injection-in-mailerup-do…