Hastymail version 1.0.1 stable and below and 1.1 development and below suffer from a cross site scripting flaw.