CVE-2025-46011: Nadh Listmonk

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Listmonk v4.1.0 (fixed in v5.0.0) is vulnerable to SQL Injection in the QuerySubscribers function which allows attackers to escalate privileges.

Affected products

  • Nadh Listmonk: from 2.4.0, before 5.0.0 (fixed in 5.0.0)

Published 2025-06-04. Last modified 2026-06-17.