CVE-2025-46011: Nadh Listmonk
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Listmonk v4.1.0 (fixed in v5.0.0) is vulnerable to SQL Injection in the QuerySubscribers function which allows attackers to escalate privileges.
Affected products
- Nadh Listmonk: from 2.4.0, before 5.0.0 (fixed in 5.0.0)
Published 2025-06-04. Last modified 2026-06-17.