VendorsNadhlistmonkall versions
Vulnerabilities

Nadh Listmonk

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2025-49136
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user
Published 2025-06-09 · Analyzed
9.0EPSS 0.015
CVE-2025-58430
listmonk Vulnerable to CSRF to XSS Chain That Can Lead to Admin Account Takeover
Published 2025-09-09 · Analyzed
8.6EPSS 0.001
CVE-2026-34828
listmonk: Active sessions remain valid after password reset and password change
Published 2026-04-02 · Analyzed
7.1EPSS 0.004
CVE-2025-46011
Listmonk v4.1.0 (fixed in v5.0.0) is vulnerable to SQL Injection in the QuerySubscribers function which allows attackers to escalate privileges.
Published 2025-06-04 · Analyzed
6.5EPSS 0.003
CVE-2026-34584
listmonk: Broken Access Control in CSV Import (Unauthorized List Assignment)
Published 2026-04-02 · Analyzed
5.4EPSS 0.003
CVE-2026-21483
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover
Published 2026-01-02 · Analyzed
5.4EPSS 0.002