Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nadh

First CVE: Jun 4, 2025Active for: 1 yearTotal CVEs: 6

Nadh maintains a focused open-source email newsletter and marketing automation platform, Listmonk, whose vulnerability profile centers on web application input-handling and access-control weaknesses. The recurring exposure patterns—cross-site scripting variants, authorization bypass, and CSRF—reflect the authentication and template-rendering attack surface inherent to web-facing user interfaces and form processing, and the vendor's disclosures frequently acquire public exploit code. Defenders should treat this vendor's updates as relevant to email campaign and subscriber-management infrastructure; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nadh over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 4, 2025
13 months ago
Most Recent CVE
Apr 2, 2026
113 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-49136MEDIUM
listmonk is a standalone, self-hosted, newsletter and mailing list manager. Starting in version 4.0.0 and prior to version 5.0.2, the `env` and `expandenv` template functions which
Jun 9, 20256.528NOYES
CVE-2026-34828HIGH
listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, a session management vulnerability allows previously issued
Apr 2, 20267.123NONO
CVE-2025-58430MEDIUM
listmonk is a standalone, self-hosted, newsletter and mailing list manager. In versions up to and including 1.1.0, every http request in addition to the session cookie `session` th
Sep 9, 20256.122NONO
CVE-2026-21483MEDIUM
listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to version 6.0.0, lower-privileged user with campaign management permissions can inject malicious
Jan 2, 20265.420NONO
CVE-2025-46011MEDIUM
Listmonk v4.1.0 (fixed in v5.0.0) is vulnerable to SQL Injection in the QuerySubscribers function which allows attackers to escalate privileges.
Jun 4, 20256.519NONO
CVE-2026-34584MEDIUM
listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, bugs in list permission checks allows users in a multi-user
Apr 2, 20265.418NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
83%
17%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (66.7%)
Unknown0 (0.0%)
Required2 (33.3%)
Privileges Required
Low4 (66.7%)
High0 (0.0%)
None2 (33.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
16.7% of CVEs· 99th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nadh.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nadh — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nadh's Products

View all 2 CNAs →

Top CWEs