We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Listmonk v4.1.0 (fixed in v5.0.0) is vulnerable to SQL Injection in the QuerySubscribers function which allows attackers to escalate privileges.
Reserved 2025-04-22 | Published 2025-06-04 | Updated 2025-06-09 | Assigner mitregithub.com/kevinroleke/security/tree/main/CVE-2025-46011
github.com/knadh/listmonk/releases/tag/v5.0.0
github.com/...ommit/4b805f885b9f5a20126ec06f8b59dc448c4af33b
github.com/knadh/listmonk/issues/2412
github.com/knadh/listmonk/releases/tag/v4.1.0
Support options