HTML Injection Vulnerability in MailerUp by Maalfer
CVE-2026-75872
6.9MEDIUM
What is CVE-2026-75872?
MailerUp prior to version 1.1.3 has a vulnerability that enables unauthenticated remote attackers to inject arbitrary HTML through the first_name field in the public subscription form. This flaw can be exploited to manipulate the content of the double opt-in verification email, allowing attackers to send messages to any chosen address while disguising the sender as the form owner, thereby compromising user security and email integrity.
Affected Version(s)
MailerUp 0 < 1.1.3
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nacho GarcĂa Egea
XoĂĄn M. Otero Jorge
Secur0 CNA
Mario Ălvarez FernĂĄndez
