CVE-2026-21483
MEDIUMlistmonk < 6.0.0 - Stored Cross-Site Scripting via Campaign or Template Injection
Title source: llmDescription
listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to version 6.0.0, lower-privileged user with campaign management permissions can inject malicious JavaScript into campaigns or templates. When a higher-privileged user (Super Admin) views or previews this content, the XSS executes in their browser context, allowing the attacker to perform privileged actions such as creating backdoor admin accounts. The attack can be weaponized via the public archive feature, where victims simply need to visit a link - no preview click required. Version 6.0.0 fixes the issue.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
https://github.com/knadh/listmonk/security/advisories/GHSA-jmr4-p576-v565
Scores
CVSS v3
5.4
EPSS
0.0020
EPSS Percentile
9.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (2)
knadh/listmonk
1.1.1 - 6.0.0Go
nadh/listmonk
< 6.0.0
Published
Jan 02, 2026
Tracked Since
Feb 18, 2026