postorius
A web user interface for GNU Mailman
Activity
- Latest release
- 1y ago
- Total releases
- 35
- Cadence
- ~2 months
- Last 12 months
- 0
Details
- License
- GPL-3.0
- First release
- Apr 15, 2014
| Version | Released | |
|---|---|---|
1.3.13
patch
1 CVE
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.3.13
patch
Dependencies (9)
+ 1 more |
|
1.3.13a1
pre
1 CVE
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.3.13a1
pre
Dependencies (9)
+ 1 more |
|
1.3.12
patch
1 CVE
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.3.12
patch
Dependencies (9)
+ 1 more |
|
1.3.11
patch
1 CVE
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.3.11
patch
Dependencies (9)
+ 1 more |
|
1.3.10
patch
1 CVE
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.3.10
patch
|
|
1.3.9
patch
1 CVE
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.3.9
patch
Dependencies (4)
|
|
1.3.8
patch
1 CVE
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.3.8
patch
|
|
1.3.7
patch
1 CVE
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.3.7
patch
|
|
1.3.6
patch
1 CVE
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.3.6
patch
|
|
1.3.6b1
pre
1 CVE
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.3.6b1
pre
|
|
1.3.5
patch
1 CVE
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.3.5
patch
|
|
1.3.4
patch
2 CVEs
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2021-40347
GHSA-v83x-78q3-gr2j
PYSEC-2021-319
May 24, 2022
GNU Mailman Postorius Access Control Issues
Medium
Network
Low
Low
None
An issue was discovered in Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 14 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
Fixed in
1.3.5
References
Updated Oct 21, 2024 · Source: OSV.dev |
1.3.4
patch
|
|
1.3.4rc1
pre
2 CVEs
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2021-40347
GHSA-v83x-78q3-gr2j
PYSEC-2021-319
May 24, 2022
GNU Mailman Postorius Access Control Issues
Medium
Network
Low
Low
None
An issue was discovered in Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 14 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
Fixed in
1.3.5
References
Updated Oct 21, 2024 · Source: OSV.dev |
1.3.4rc1
pre
|
|
1.3.3
patch
2 CVEs
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2021-40347
GHSA-v83x-78q3-gr2j
PYSEC-2021-319
May 24, 2022
GNU Mailman Postorius Access Control Issues
Medium
Network
Low
Low
None
An issue was discovered in Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 14 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
Fixed in
1.3.5
References
Updated Oct 21, 2024 · Source: OSV.dev |
1.3.3
patch
|
|
1.3.3rc2
pre
2 CVEs
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2021-40347
GHSA-v83x-78q3-gr2j
PYSEC-2021-319
May 24, 2022
GNU Mailman Postorius Access Control Issues
Medium
Network
Low
Low
None
An issue was discovered in Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 14 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
Fixed in
1.3.5
References
Updated Oct 21, 2024 · Source: OSV.dev |
1.3.3rc2
pre
|
|
1.3.3rc1
pre
2 CVEs
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2021-40347
GHSA-v83x-78q3-gr2j
PYSEC-2021-319
May 24, 2022
GNU Mailman Postorius Access Control Issues
Medium
Network
Low
Low
None
An issue was discovered in Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 14 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
Fixed in
1.3.5
References
Updated Oct 21, 2024 · Source: OSV.dev |
1.3.3rc1
pre
|
|
1.3.2
patch
2 CVEs
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2021-40347
GHSA-v83x-78q3-gr2j
PYSEC-2021-319
May 24, 2022
GNU Mailman Postorius Access Control Issues
Medium
Network
Low
Low
None
An issue was discovered in Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 14 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
Fixed in
1.3.5
References
Updated Oct 21, 2024 · Source: OSV.dev |
1.3.2
patch
Dependencies (4)
|
|
1.3.1
patch
2 CVEs
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2021-40347
GHSA-v83x-78q3-gr2j
PYSEC-2021-319
May 24, 2022
GNU Mailman Postorius Access Control Issues
Medium
Network
Low
Low
None
An issue was discovered in Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 14 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
Fixed in
1.3.5
References
Updated Oct 21, 2024 · Source: OSV.dev |
1.3.1
patch
Dependencies (4)
|
|
1.3.0
minor
2 CVEs
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2021-40347
GHSA-v83x-78q3-gr2j
PYSEC-2021-319
May 24, 2022
GNU Mailman Postorius Access Control Issues
Medium
Network
Low
Low
None
An issue was discovered in Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 14 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
Fixed in
1.3.5
References
Updated Oct 21, 2024 · Source: OSV.dev |
1.3.0
minor
Dependencies (4)
|
|
1.2.4
patch
2 CVEs
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2021-40347
GHSA-v83x-78q3-gr2j
PYSEC-2021-319
May 24, 2022
GNU Mailman Postorius Access Control Issues
Medium
Network
Low
Low
None
An issue was discovered in Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 14 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
Fixed in
1.3.5
References
Updated Oct 21, 2024 · Source: OSV.dev |
1.2.4
patch
|
|
1.2.3
patch
2 CVEs
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2021-40347
GHSA-v83x-78q3-gr2j
PYSEC-2021-319
May 24, 2022
GNU Mailman Postorius Access Control Issues
Medium
Network
Low
Low
None
An issue was discovered in Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 14 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
Fixed in
1.3.5
References
Updated Oct 21, 2024 · Source: OSV.dev |
1.2.3
patch
|
|
1.2.2
patch
2 CVEs
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2021-40347
GHSA-v83x-78q3-gr2j
PYSEC-2021-319
May 24, 2022
GNU Mailman Postorius Access Control Issues
Medium
Network
Low
Low
None
An issue was discovered in Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 14 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
Fixed in
1.3.5
References
Updated Oct 21, 2024 · Source: OSV.dev |
1.2.2
patch
|
|
1.2.1
patch
2 CVEs
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2021-40347
GHSA-v83x-78q3-gr2j
PYSEC-2021-319
May 24, 2022
GNU Mailman Postorius Access Control Issues
Medium
Network
Low
Low
None
An issue was discovered in Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 14 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
Fixed in
1.3.5
References
Updated Oct 21, 2024 · Source: OSV.dev |
1.2.1
patch
Dependencies (3)
|
|
1.2.0
minor
2 CVEs
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2021-40347
GHSA-v83x-78q3-gr2j
PYSEC-2021-319
May 24, 2022
GNU Mailman Postorius Access Control Issues
Medium
Network
Low
Low
None
An issue was discovered in Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 14 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
Fixed in
1.3.5
References
Updated Oct 21, 2024 · Source: OSV.dev |
1.2.0
minor
|
|
1.2.0a1
pre
2 CVEs
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2021-40347
GHSA-v83x-78q3-gr2j
PYSEC-2021-319
May 24, 2022
GNU Mailman Postorius Access Control Issues
Medium
Network
Low
Low
None
An issue was discovered in Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 14 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
Fixed in
1.3.5
References
Updated Oct 21, 2024 · Source: OSV.dev |
1.2.0a1
pre
|
|
1.1.2
patch
2 CVEs
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2021-40347
GHSA-v83x-78q3-gr2j
PYSEC-2021-319
May 24, 2022
GNU Mailman Postorius Access Control Issues
Medium
Network
Low
Low
None
An issue was discovered in Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 14 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
Fixed in
1.3.5
References
Updated Oct 21, 2024 · Source: OSV.dev |
1.1.2
patch
|
|
1.1.1
patch
2 CVEs
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2021-40347
GHSA-v83x-78q3-gr2j
PYSEC-2021-319
May 24, 2022
GNU Mailman Postorius Access Control Issues
Medium
Network
Low
Low
None
An issue was discovered in Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 14 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
Fixed in
1.3.5
References
Updated Oct 21, 2024 · Source: OSV.dev |
1.1.1
patch
|
|
1.1.0
minor
2 CVEs
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2021-40347
GHSA-v83x-78q3-gr2j
PYSEC-2021-319
May 24, 2022
GNU Mailman Postorius Access Control Issues
Medium
Network
Low
Low
None
An issue was discovered in Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 14 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
Fixed in
1.3.5
References
Updated Oct 21, 2024 · Source: OSV.dev |
1.1.0
minor
|
|
1.0.3
patch
2 CVEs
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2021-40347
GHSA-v83x-78q3-gr2j
PYSEC-2021-319
May 24, 2022
GNU Mailman Postorius Access Control Issues
Medium
Network
Low
Low
None
An issue was discovered in Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 14 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
Fixed in
1.3.5
References
Updated Oct 21, 2024 · Source: OSV.dev |
1.0.3
patch
|
|
1.0.2
patch
2 CVEs
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2021-40347
GHSA-v83x-78q3-gr2j
PYSEC-2021-319
May 24, 2022
GNU Mailman Postorius Access Control Issues
Medium
Network
Low
Low
None
An issue was discovered in Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 14 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
Fixed in
1.3.5
References
Updated Oct 21, 2024 · Source: OSV.dev |
1.0.2
patch
|
|
1.0.1
patch
2 CVEs
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2021-40347
GHSA-v83x-78q3-gr2j
PYSEC-2021-319
May 24, 2022
GNU Mailman Postorius Access Control Issues
Medium
Network
Low
Low
None
An issue was discovered in Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 14 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
Fixed in
1.3.5
References
Updated Oct 21, 2024 · Source: OSV.dev |
1.0.1
patch
|
|
1.0.0
initial
2 CVEs
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2021-40347
GHSA-v83x-78q3-gr2j
PYSEC-2021-319
May 24, 2022
GNU Mailman Postorius Access Control Issues
Medium
Network
Low
Low
None
An issue was discovered in Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 14 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
Fixed in
1.3.5
References
Updated Oct 21, 2024 · Source: OSV.dev |
1.0.0
initial
|
|
1.0.0b3
pre
2 CVEs
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2021-40347
GHSA-v83x-78q3-gr2j
PYSEC-2021-319
May 24, 2022
GNU Mailman Postorius Access Control Issues
Medium
Network
Low
Low
None
An issue was discovered in Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 14 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
Fixed in
1.3.5
References
Updated Oct 21, 2024 · Source: OSV.dev |
1.0.0b3
pre
|
|
1.0.0b1
pre
2 CVEs
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2021-40347
GHSA-v83x-78q3-gr2j
PYSEC-2021-319
May 24, 2022
GNU Mailman Postorius Access Control Issues
Medium
Network
Low
Low
None
An issue was discovered in Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 14 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
Fixed in
1.3.5
References
Updated Oct 21, 2024 · Source: OSV.dev |
1.0.0b1
pre
|
|
1.0.0a2
pre
2 CVEs
CVE-2026-44742
PYSEC-2026-2891
GHSA-r7c9-7pjq-hmm8
Jul 13, 2026
Postorius is vulnerable to XSS
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 25 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.13a1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
1.3.5
1.3.6
1.3.6b1
1.3.7
1.3.8
1.3.9
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2021-40347
GHSA-v83x-78q3-gr2j
PYSEC-2021-319
May 24, 2022
GNU Mailman Postorius Access Control Issues
Medium
Network
Low
Low
None
An issue was discovered in Affected versions
1.0.0
1.0.0a1
1.0.0a2
1.0.0b1
1.0.0b2
1.0.0b3
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
+ 14 more Show less
1.2.0
1.2.0a1
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.3.2
1.3.3
1.3.3rc1
1.3.3rc2
1.3.4
1.3.4rc1
Fixed in
1.3.5
References
Updated Oct 21, 2024 · Source: OSV.dev |
1.0.0a2
pre
|