Vulnerability Description
HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the first_name field of the subscription request, which is interpolated unescaped into the double opt-in verification email.
Related Weaknesses (CWE)
References
- https://github.com/maalfer/mailerup/commit/da4aedc9621911df4ce0cc8f0b321dd6d10f4
- https://github.com/maalfer/mailerup/releases/tag/v1.1.3
- https://secur0.com/en/cna/cve-list/cve-2026-75872-html-injection-in-mailerup-dou
FAQ
What is CVE-2026-75872?
CVE-2026-75872 is a documented vulnerability. HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-c...
How severe is CVE-2026-75872?
CVSS scoring is not yet available for CVE-2026-75872. Check NVD for updates.
Is there a patch for CVE-2026-75872?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.