# CVE-2026-75872

## Summary

- **CVE ID:** CVE-2026-75872
- **Severity:** MEDIUM
- **CVSS Score:** 6.9 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-80
- **Published:** Aug 18, 2026
- **Last Modified:** Aug 18, 2026

## Description

HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the first_name field of the subscription request, which is interpolated unescaped into the double opt-in verification email.

## Affected Products

- maalfer — MailerUp (0)

## References

- [CNA](https://github.com/maalfer/mailerup/commit/da4aedc9621911df4ce0cc8f0b321dd6d10f40a5)
- [CNA](https://github.com/maalfer/mailerup/releases/tag/v1.1.3)
- [CNA](https://secur0.com/en/cna/cve-list/cve-2026-75872-html-injection-in-mailerup-double-optin-verification-email)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.71%
- **EPSS Percentile:** 51.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._