{"id":"CVE-2026-75872","summary":"HTML Injection in MailerUp double opt-in verification email","details":"HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the first_name field of the subscription request, which is interpolated unescaped into the double opt-in verification email.","modified":"2026-09-03T03:30:38.784397169Z","published":"2026-08-18T14:06:37.102Z","database_specific":{"cna_assigner":"Secur0","cwe_ids":["CWE-80"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75872.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75872.json"},{"type":"ADVISORY","url":"https://github.com/maalfer/mailerup/releases/tag/v1.1.3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75872"},{"type":"FIX","url":"https://github.com/maalfer/mailerup/commit/da4aedc9621911df4ce0cc8f0b321dd6d10f40a5"},{"type":"PACKAGE","url":"https://github.com/maalfer/mailerup"},{"type":"ARTICLE","url":"https://secur0.com/en/cna/cve-list/cve-2026-75872-html-injection-in-mailerup-double-optin-verification-email"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/maalfer/mailerup","events":[{"introduced":"0"},{"fixed":"da4aedc9621911df4ce0cc8f0b321dd6d10f40a5"}],"database_specific":{"source":["AFFECTED_FIELD","DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"1.1.3"}]}}],"versions":["v1.1.2","v1.1.1","v1.1.0","v1.0.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75872.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}