Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27482 | listmonk is a standalone, self-hosted, newsletter and mailing list manager. In versions up to and including 1.1.0, every http request in addition to the session cookie `session` there included `nonce`. The value is not checked and validated by the backend, removing `nonce` allows the requests to be processed correctly. This may seem harmless, but if chained to other vulnerabilities it can become a critical vulnerability. Cross-site request forgery and cross-site scripting chained together can result in improper admin account creation. As of time of publication, no patched versions are available. |
Github GHSA |
GHSA-rf24-wg77-gq7w | listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover |
Fri, 10 Oct 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nadh:listmonk:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Fri, 12 Sep 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Listmok Project
Listmok Project listmonk Nadh Nadh listmonk |
|
| Vendors & Products |
Listmok Project
Listmok Project listmonk Nadh Nadh listmonk |
Wed, 10 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Sep 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | listmonk is a standalone, self-hosted, newsletter and mailing list manager. In versions up to and including 1.1.0, every http request in addition to the session cookie `session` there included `nonce`. The value is not checked and validated by the backend, removing `nonce` allows the requests to be processed correctly. This may seem harmless, but if chained to other vulnerabilities it can become a critical vulnerability. Cross-site request forgery and cross-site scripting chained together can result in improper admin account creation. As of time of publication, no patched versions are available. | |
| Title | listmonk Vulnerable to CSRF to XSS Chain That Can Lead to Admin Account Takeover | |
| Weaknesses | CWE-352 CWE-79 CWE-80 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-10T13:55:42.949Z
Reserved: 2025-09-01T20:03:06.531Z
Link: CVE-2025-58430
Updated: 2025-09-10T13:55:22.453Z
Status : Analyzed
Published: 2025-09-09T20:15:48.450
Modified: 2025-10-10T21:49:03.133
Link: CVE-2025-58430
No data.
OpenCVE Enrichment
Updated: 2025-09-12T09:11:38Z
EUVD
Github GHSA