Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

A confirmed-exploited cross-site scripting vulnerability in Postorius, the administrative web interface for GNU Mailman 3 mailing list software, allows attackers to inject malicious JavaScript into the held-messages queue viewed by mail administrators and list moderators. The vulnerability is listed on the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild as of May 2026. Organizations running Postorius through version 1.3.13 face direct risk of administrator account compromise, credential theft, and unauthorized control of mailing list infrastructure.

Author

Tech Jacks Solutions