Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16925 | Listmonk v4.1.0 (fixed in v5.0.0) is vulnerable to SQL Injection in the QuerySubscribers function which allows attackers to escalate privileges. |
Wed, 15 Oct 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nadh
Nadh listmonk |
|
| CPEs | cpe:2.3:a:nadh:listmonk:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nadh
Nadh listmonk |
Mon, 09 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Listmonk v2.4.0 through v4.1.0 is vulnerable to SQL Injection in the QuerySubscribers function which allows attackers to escalate privileges. | Listmonk v4.1.0 (fixed in v5.0.0) is vulnerable to SQL Injection in the QuerySubscribers function which allows attackers to escalate privileges. |
| References |
|
Wed, 04 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Wed, 04 Jun 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Listmonk v2.4.0 through v4.1.0 is vulnerable to SQL Injection in the QuerySubscribers function which allows attackers to escalate privileges. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-06-09T20:56:28.471Z
Reserved: 2025-04-22T00:00:00.000Z
Link: CVE-2025-46011
Updated: 2025-06-04T20:45:52.344Z
Status : Analyzed
Published: 2025-06-04T20:15:23.313
Modified: 2025-10-15T17:54:53.033
Link: CVE-2025-46011
No data.
OpenCVE Enrichment
No data.
EUVD