PT-2026-38553 · Postorius · Postorius

Published

2026-05-07

·

Updated

2026-05-07

·

CVE-2026-44742

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-44742

Affected Products

Postorius