Cross-Site Scripting Vulnerability in Listmonk by Knadh
CVE-2026-21483

5.4MEDIUM

Key Information:

Vendor

Knadh

Status
Vendor
CVE Published:
2 January 2026

What is CVE-2026-21483?

Listmonk is a self-hosted newsletter and mailing list manager that is vulnerable to Cross-Site Scripting (XSS) attacks. Prior to version 6.0.0, users with lower privileges who manage campaigns can insert malicious JavaScript into campaign content or templates. When viewed by higher-privileged users, such as Super Admins, this malicious script executes in their browsers, enabling attackers to perform unauthorized actions, including the creation of backdoor admin accounts. Furthermore, this vulnerability can be exploited via the public archive feature, requiring victims to only visit a link without prior content preview, making it particularly dangerous. The issue has been addressed in version 6.0.0.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

listmonk < 6.0.0

References

CVSS V4

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.