github.com/knadh/listmonk
Activity
- Latest release
- 5y ago
- Total releases
- 20
- Cadence
- ~24 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- First release
- Jul 12, 2019
| Version | Released | |
|---|---|---|
v1.1.0
minor
3 CVEs
CVE-2026-21483
GO-2026-4277
GHSA-jmr4-p576-v565
Jan 12, 2026
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v1.1.1 before v6.0.0. Fixed in
1.1.1-0.20251231125615-74dc5a01cfbb
References Updated Jan 12, 2026 · Source: OSV.dev
CVE-2025-58430
GO-2025-3943
GHSA-rf24-wg77-gq7w
Sep 17, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49136
GO-2025-3745
GHSA-jc7g-x28f-3v3h
Jun 10, 2025
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v4.0.0 before v5.0.2. References Updated Jun 10, 2025 · Source: OSV.dev |
v1.1.0
minor
Dependencies (16)
+ 8 more |
|
v1.0.0
initial
3 CVEs
CVE-2026-21483
GO-2026-4277
GHSA-jmr4-p576-v565
Jan 12, 2026
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v1.1.1 before v6.0.0. Fixed in
1.1.1-0.20251231125615-74dc5a01cfbb
References Updated Jan 12, 2026 · Source: OSV.dev
CVE-2025-58430
GO-2025-3943
GHSA-rf24-wg77-gq7w
Sep 17, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49136
GO-2025-3745
GHSA-jc7g-x28f-3v3h
Jun 10, 2025
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v4.0.0 before v5.0.2. References Updated Jun 10, 2025 · Source: OSV.dev |
v1.0.0
initial
Dependencies (16)
+ 8 more |
|
v0.9.0-beta
pre
3 CVEs
CVE-2026-21483
GO-2026-4277
GHSA-jmr4-p576-v565
Jan 12, 2026
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v1.1.1 before v6.0.0. Fixed in
1.1.1-0.20251231125615-74dc5a01cfbb
References Updated Jan 12, 2026 · Source: OSV.dev
CVE-2025-58430
GO-2025-3943
GHSA-rf24-wg77-gq7w
Sep 17, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49136
GO-2025-3745
GHSA-jc7g-x28f-3v3h
Jun 10, 2025
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v4.0.0 before v5.0.2. References Updated Jun 10, 2025 · Source: OSV.dev |
v0.9.0-beta
pre
Dependencies (15)
+ 7 more |
|
v0.8.0-beta
pre
3 CVEs
CVE-2026-21483
GO-2026-4277
GHSA-jmr4-p576-v565
Jan 12, 2026
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v1.1.1 before v6.0.0. Fixed in
1.1.1-0.20251231125615-74dc5a01cfbb
References Updated Jan 12, 2026 · Source: OSV.dev
CVE-2025-58430
GO-2025-3943
GHSA-rf24-wg77-gq7w
Sep 17, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49136
GO-2025-3745
GHSA-jc7g-x28f-3v3h
Jun 10, 2025
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v4.0.0 before v5.0.2. References Updated Jun 10, 2025 · Source: OSV.dev |
v0.8.0-beta
pre
Dependencies (16)
+ 8 more |
|
v0.7.0-alpha
pre
3 CVEs
CVE-2026-21483
GO-2026-4277
GHSA-jmr4-p576-v565
Jan 12, 2026
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v1.1.1 before v6.0.0. Fixed in
1.1.1-0.20251231125615-74dc5a01cfbb
References Updated Jan 12, 2026 · Source: OSV.dev
CVE-2025-58430
GO-2025-3943
GHSA-rf24-wg77-gq7w
Sep 17, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49136
GO-2025-3745
GHSA-jc7g-x28f-3v3h
Jun 10, 2025
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v4.0.0 before v5.0.2. References Updated Jun 10, 2025 · Source: OSV.dev |
v0.7.0-alpha
pre
Dependencies (15)
+ 7 more |
|
v0.6.2-alpha
pre
3 CVEs
CVE-2026-21483
GO-2026-4277
GHSA-jmr4-p576-v565
Jan 12, 2026
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v1.1.1 before v6.0.0. Fixed in
1.1.1-0.20251231125615-74dc5a01cfbb
References Updated Jan 12, 2026 · Source: OSV.dev
CVE-2025-58430
GO-2025-3943
GHSA-rf24-wg77-gq7w
Sep 17, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49136
GO-2025-3745
GHSA-jc7g-x28f-3v3h
Jun 10, 2025
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v4.0.0 before v5.0.2. References Updated Jun 10, 2025 · Source: OSV.dev |
v0.6.2-alpha
pre
Dependencies (14)
+ 6 more |
|
v0.6.1-alpha
pre
3 CVEs
CVE-2026-21483
GO-2026-4277
GHSA-jmr4-p576-v565
Jan 12, 2026
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v1.1.1 before v6.0.0. Fixed in
1.1.1-0.20251231125615-74dc5a01cfbb
References Updated Jan 12, 2026 · Source: OSV.dev
CVE-2025-58430
GO-2025-3943
GHSA-rf24-wg77-gq7w
Sep 17, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49136
GO-2025-3745
GHSA-jc7g-x28f-3v3h
Jun 10, 2025
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v4.0.0 before v5.0.2. References Updated Jun 10, 2025 · Source: OSV.dev |
v0.6.1-alpha
pre
Dependencies (14)
+ 6 more |
|
v0.6.0-alpha
pre
3 CVEs
CVE-2026-21483
GO-2026-4277
GHSA-jmr4-p576-v565
Jan 12, 2026
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v1.1.1 before v6.0.0. Fixed in
1.1.1-0.20251231125615-74dc5a01cfbb
References Updated Jan 12, 2026 · Source: OSV.dev
CVE-2025-58430
GO-2025-3943
GHSA-rf24-wg77-gq7w
Sep 17, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49136
GO-2025-3745
GHSA-jc7g-x28f-3v3h
Jun 10, 2025
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v4.0.0 before v5.0.2. References Updated Jun 10, 2025 · Source: OSV.dev |
v0.6.0-alpha
pre
Dependencies (14)
+ 6 more |
|
v0.5.2-alpha
pre
3 CVEs
CVE-2026-21483
GO-2026-4277
GHSA-jmr4-p576-v565
Jan 12, 2026
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v1.1.1 before v6.0.0. Fixed in
1.1.1-0.20251231125615-74dc5a01cfbb
References Updated Jan 12, 2026 · Source: OSV.dev
CVE-2025-58430
GO-2025-3943
GHSA-rf24-wg77-gq7w
Sep 17, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49136
GO-2025-3745
GHSA-jc7g-x28f-3v3h
Jun 10, 2025
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v4.0.0 before v5.0.2. References Updated Jun 10, 2025 · Source: OSV.dev |
v0.5.2-alpha
pre
Dependencies (12)
+ 4 more |
|
v0.5.1-alpha
pre
3 CVEs
CVE-2026-21483
GO-2026-4277
GHSA-jmr4-p576-v565
Jan 12, 2026
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v1.1.1 before v6.0.0. Fixed in
1.1.1-0.20251231125615-74dc5a01cfbb
References Updated Jan 12, 2026 · Source: OSV.dev
CVE-2025-58430
GO-2025-3943
GHSA-rf24-wg77-gq7w
Sep 17, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49136
GO-2025-3745
GHSA-jc7g-x28f-3v3h
Jun 10, 2025
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v4.0.0 before v5.0.2. References Updated Jun 10, 2025 · Source: OSV.dev |
v0.5.1-alpha
pre
Dependencies (12)
+ 4 more |
|
v0.5.0-alpha
pre
3 CVEs
CVE-2026-21483
GO-2026-4277
GHSA-jmr4-p576-v565
Jan 12, 2026
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v1.1.1 before v6.0.0. Fixed in
1.1.1-0.20251231125615-74dc5a01cfbb
References Updated Jan 12, 2026 · Source: OSV.dev
CVE-2025-58430
GO-2025-3943
GHSA-rf24-wg77-gq7w
Sep 17, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49136
GO-2025-3745
GHSA-jc7g-x28f-3v3h
Jun 10, 2025
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v4.0.0 before v5.0.2. References Updated Jun 10, 2025 · Source: OSV.dev |
v0.5.0-alpha
pre
Dependencies (12)
+ 4 more |
|
v0.4.0-alpha
pre
3 CVEs
CVE-2026-21483
GO-2026-4277
GHSA-jmr4-p576-v565
Jan 12, 2026
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v1.1.1 before v6.0.0. Fixed in
1.1.1-0.20251231125615-74dc5a01cfbb
References Updated Jan 12, 2026 · Source: OSV.dev
CVE-2025-58430
GO-2025-3943
GHSA-rf24-wg77-gq7w
Sep 17, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49136
GO-2025-3745
GHSA-jc7g-x28f-3v3h
Jun 10, 2025
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v4.0.0 before v5.0.2. References Updated Jun 10, 2025 · Source: OSV.dev |
v0.4.0-alpha
pre
Dependencies (15)
+ 7 more |
|
v0.3.3-alpha
pre
3 CVEs
CVE-2026-21483
GO-2026-4277
GHSA-jmr4-p576-v565
Jan 12, 2026
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v1.1.1 before v6.0.0. Fixed in
1.1.1-0.20251231125615-74dc5a01cfbb
References Updated Jan 12, 2026 · Source: OSV.dev
CVE-2025-58430
GO-2025-3943
GHSA-rf24-wg77-gq7w
Sep 17, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49136
GO-2025-3745
GHSA-jc7g-x28f-3v3h
Jun 10, 2025
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v4.0.0 before v5.0.2. References Updated Jun 10, 2025 · Source: OSV.dev |
v0.3.3-alpha
pre
Dependencies (15)
+ 7 more |
|
v0.3.2-alpha
pre
3 CVEs
CVE-2026-21483
GO-2026-4277
GHSA-jmr4-p576-v565
Jan 12, 2026
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v1.1.1 before v6.0.0. Fixed in
1.1.1-0.20251231125615-74dc5a01cfbb
References Updated Jan 12, 2026 · Source: OSV.dev
CVE-2025-58430
GO-2025-3943
GHSA-rf24-wg77-gq7w
Sep 17, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49136
GO-2025-3745
GHSA-jc7g-x28f-3v3h
Jun 10, 2025
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v4.0.0 before v5.0.2. References Updated Jun 10, 2025 · Source: OSV.dev |
v0.3.2-alpha
pre
Dependencies (15)
+ 7 more |
|
v0.3.1-alpha
pre
3 CVEs
CVE-2026-21483
GO-2026-4277
GHSA-jmr4-p576-v565
Jan 12, 2026
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v1.1.1 before v6.0.0. Fixed in
1.1.1-0.20251231125615-74dc5a01cfbb
References Updated Jan 12, 2026 · Source: OSV.dev
CVE-2025-58430
GO-2025-3943
GHSA-rf24-wg77-gq7w
Sep 17, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49136
GO-2025-3745
GHSA-jc7g-x28f-3v3h
Jun 10, 2025
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v4.0.0 before v5.0.2. References Updated Jun 10, 2025 · Source: OSV.dev |
v0.3.1-alpha
pre
Dependencies (15)
+ 7 more |
|
v0.3.0-alpha
pre
3 CVEs
CVE-2026-21483
GO-2026-4277
GHSA-jmr4-p576-v565
Jan 12, 2026
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v1.1.1 before v6.0.0. Fixed in
1.1.1-0.20251231125615-74dc5a01cfbb
References Updated Jan 12, 2026 · Source: OSV.dev
CVE-2025-58430
GO-2025-3943
GHSA-rf24-wg77-gq7w
Sep 17, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49136
GO-2025-3745
GHSA-jc7g-x28f-3v3h
Jun 10, 2025
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v4.0.0 before v5.0.2. References Updated Jun 10, 2025 · Source: OSV.dev |
v0.3.0-alpha
pre
Dependencies (15)
+ 7 more |
|
v0.2.2-alpha
pre
3 CVEs
CVE-2026-21483
GO-2026-4277
GHSA-jmr4-p576-v565
Jan 12, 2026
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v1.1.1 before v6.0.0. Fixed in
1.1.1-0.20251231125615-74dc5a01cfbb
References Updated Jan 12, 2026 · Source: OSV.dev
CVE-2025-58430
GO-2025-3943
GHSA-rf24-wg77-gq7w
Sep 17, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49136
GO-2025-3745
GHSA-jc7g-x28f-3v3h
Jun 10, 2025
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v4.0.0 before v5.0.2. References Updated Jun 10, 2025 · Source: OSV.dev |
v0.2.2-alpha
pre
Dependencies (13)
+ 5 more |
|
v0.2.1-alpha
pre
3 CVEs
CVE-2026-21483
GO-2026-4277
GHSA-jmr4-p576-v565
Jan 12, 2026
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v1.1.1 before v6.0.0. Fixed in
1.1.1-0.20251231125615-74dc5a01cfbb
References Updated Jan 12, 2026 · Source: OSV.dev
CVE-2025-58430
GO-2025-3943
GHSA-rf24-wg77-gq7w
Sep 17, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49136
GO-2025-3745
GHSA-jc7g-x28f-3v3h
Jun 10, 2025
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v4.0.0 before v5.0.2. References Updated Jun 10, 2025 · Source: OSV.dev |
v0.2.1-alpha
pre
Dependencies (13)
+ 5 more |
|
v0.2.0-alpha
pre
3 CVEs
CVE-2026-21483
GO-2026-4277
GHSA-jmr4-p576-v565
Jan 12, 2026
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v1.1.1 before v6.0.0. Fixed in
1.1.1-0.20251231125615-74dc5a01cfbb
References Updated Jan 12, 2026 · Source: OSV.dev
CVE-2025-58430
GO-2025-3943
GHSA-rf24-wg77-gq7w
Sep 17, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49136
GO-2025-3745
GHSA-jc7g-x28f-3v3h
Jun 10, 2025
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v4.0.0 before v5.0.2. References Updated Jun 10, 2025 · Source: OSV.dev |
v0.2.0-alpha
pre
Dependencies (13)
+ 5 more |
|
v0.1.2-alpha
pre
3 CVEs
CVE-2026-21483
GO-2026-4277
GHSA-jmr4-p576-v565
Jan 12, 2026
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v1.1.1 before v6.0.0. Fixed in
1.1.1-0.20251231125615-74dc5a01cfbb
References Updated Jan 12, 2026 · Source: OSV.dev
CVE-2025-58430
GO-2025-3943
GHSA-rf24-wg77-gq7w
Sep 17, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-49136
GO-2025-3745
GHSA-jc7g-x28f-3v3h
Jun 10, 2025
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/knadh/listmonk from v4.0.0 before v5.0.2. References Updated Jun 10, 2025 · Source: OSV.dev |
v0.1.2-alpha
pre
Dependencies (13)
+ 5 more |