📦 Listmonk

by Nadh

🔍 What is Listmonk?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-21483

MEDIUM CVSS 5.4 Jan 2, 2026

This is a stored cross-site scripting (XSS) vulnerability in listmonk that allows lower-privileged users to inject malicious JavaScript into campaigns or templates. When higher-privileged users view t...

CVE-2025-58430

MEDIUM CVSS 6.1 Sep 9, 2025

listmonk versions up to 1.1.0 include a nonce parameter in HTTP requests that isn't validated by the backend, allowing requests to be processed without it. This can be chained with other vulnerabiliti...

CVE-2025-46011

MEDIUM CVSS 6.5 Jun 4, 2025

Listmonk v4.1.0 contains a SQL injection vulnerability in the QuerySubscribers function that allows attackers to execute arbitrary SQL commands. This can lead to privilege escalation and unauthorized ...