CVE-2018-13796: GNU Mailman

Medium severity, CVSS 6.5. EPSS: 2.5% chance of exploitation in the next 30 days.

An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web page from a trusted site.

Affected products

  • GNU Mailman: before 2.1.28 (fixed in 2.1.28)

Published 2018-07-12. Last modified 2026-06-17.