ZeroHour

CVE-2025-46011

CVSS 3.1
6.5 medium
EPSS
<1%p22
Published
()
Modified
Description

Listmonk v4.1.0 (fixed in v5.0.0) is vulnerable to SQL Injection in the QuerySubscribers function which allows attackers to escalate privileges.

Vendors
nadh
Products
listmonk
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.