Nadh maintains a focused open-source email newsletter and marketing automation platform, Listmonk, whose vulnerability profile centers on web application input-handling and access-control weaknesses. The recurring exposure patterns—cross-site scripting variants, authorization bypass, and CSRF—reflect the authentication and template-rendering attack surface inherent to web-facing user interfaces and form processing, and the vendor's disclosures frequently acquire public exploit code. Defenders should treat this vendor's updates as relevant to email campaign and subscriber-management infrastructure; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nadh over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-49136MEDIUM listmonk is a standalone, self-hosted, newsletter and mailing list manager. Starting in version 4.0.0 and prior to version 5.0.2, the `env` and `expandenv` template functions which | Jun 9, 2025 | 6.5 | 28 | NO | YES |
CVE-2026-34828HIGH listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, a session management vulnerability allows previously issued | Apr 2, 2026 | 7.1 | 23 | NO | NO |
CVE-2025-58430MEDIUM listmonk is a standalone, self-hosted, newsletter and mailing list manager. In versions up to and including 1.1.0, every http request in addition to the session cookie `session` th | Sep 9, 2025 | 6.1 | 22 | NO | NO |
CVE-2026-21483MEDIUM listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to version 6.0.0, lower-privileged user with campaign management permissions can inject malicious | Jan 2, 2026 | 5.4 | 20 | NO | NO |
CVE-2025-46011MEDIUM Listmonk v4.1.0 (fixed in v5.0.0) is vulnerable to SQL Injection in the QuerySubscribers function which allows attackers to escalate privileges. | Jun 4, 2025 | 6.5 | 19 | NO | NO |
CVE-2026-34584MEDIUM listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, bugs in list permission checks allows users in a multi-user | Apr 2, 2026 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nadh.
Media articles that mention a CVE ID that affects a product developed by Nadh — matched by CVE ID, not by vendor name.