See how mailerup compares to other vendors in security performance
HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the firstname field of the subscription request, which is interpolated unescaped into the double opt-in verification email.