SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-75872

MEDIUM · CVSS 6.9 EPSS 0.71% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The public subscription form in maalfer MailerUp versions prior to 1.1.3 is vulnerable to HTML injection, allowing unauthenticated remote attackers to exploit the first_name field to send arbitrary HTML content in verification emails. This can lead to phishing attacks or other malicious activities, as the emails appear to come from the legitimate form owner's identity. Organizations using this application should prioritize patching to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75872
Severity
MEDIUM
CVSS
6.9
EPSS
0.71%

Original NVD Description

HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the first_name field of the subscription request, which is interpolated unescaped into the double opt-in verification email.