CVE 5.4 MEDIUM

listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover_CVE-2026-21483

5.4 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:P

Description

listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to version 6.0.0, lower-privileged user with campaign management permissions can inject malicious JavaScript into campaigns or templates. When a higher-privileged user (Super Admin) views or previews this content, the XSS executes in their browser context, allowing the attacker to perform privileged actions such as creating backdoor admin accounts. The attack can be weaponized via the public archive feature, where victims simply need to visit a link - no preview click required. Version 6.0.0 fixes the issue.

Basic Information

ID CVE-2026-21483
Source GitHub_M
Published Jan 2, 2026 at 20:57
Modified Jan 2, 2026 at 21:18

Affected Product

Vendor knadh
Product listmonk
Version < 6.0.0
Affected Versions knadh listmonk < 6.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.