mailman/postorius

mailman/postorius

Releases37
Frequency4 months 5 days
Last Release
Stars89
The New Mailman Web UI

CVE History

CVEPublishedCVSS v3CVSS v2
7.2 HIGH

Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.

5.4 MEDIUM5.5 MEDIUM

An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) can send a crafted POST request to unsubscribe any user from a mailing list, also revealing whether that address was subscribed in the first place.