Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2026-05-12T16:20:35Z",
"nvd_published_at": "2026-05-07T19:16:02Z",
"severity": "HIGH"
}