
🚨*CVE* CVE-2026-44742 Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026. https://www.cve.org/CVERecord?id=CVE-2026-44742 ----- Traducción: CVE-2026-44742 Postorius hasta 1.… http://infoflow.cloud`
Post summary
CVE-2026‑44742 in Postorius allows unsanitized HTML in message subjects, enabling XSS attacks that were actively exploited in May 2026.

