The mass emailing features do not sanitize the content of the HTML emails.
Impact
A malicious user could use this issue to facilitate a phishing attempt or to indirectly exploit issues in the recipients mail clients.
CVSSv3.1 score: 4.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N)
References
CWE 79
OWASP Cross-site Scripting
CVE-2025-27156
Acknowledgements
This issue has been found thanks to Psalm 6 taint analysis feature.