VYPR

MailerUp

by MailerUp

Source repositories

CVEs (2)

  • CVE-2026-13164HigJun 24, 2026
    risk 0.50cvss epss 0.01

    Missing Authentication for Critical Function (CWE-306) in the RegisterView (apps/accounts/views.py), exposed at POST /api/auth/register/, in MailerUp <1.0.1 allows a remote, unauthenticated attacker to self-register a working account on instances where registration is intended…

  • CVE-2026-75872MedAug 18, 2026
    risk 0.38cvss epss 0.01

    HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the…