← Back

Postorius

postorius

Vendor: Postorius Project • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Postorius Project
1Postorius
Jun 17, 2026
May 7, 2026
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.
1Postorius Project
1Postorius
Jun 17, 2026
Sep 10, 2021
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) can send a crafted POST request to unsubscribe any user from a mailing list, also revealing whether th...Show more
An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) can send a crafted POST request to unsubscribe any user from a mailing list, also revealing whether that address was subscribed in the first place.Show less