Skip to content
Noroxi

nadh records

6 published records for vendor nadh.

All records

6 records
  • listmonk Vulnerable to CSRF to XSS Chain That Can Lead to Admin Account Takeover

    HighCVSS 8.6No exploitEPSS 0%

    nadh · listmonkSep 9, 2025

  • listmonk: Active sessions remain valid after password reset and password change

    HighCVSS 7.1Proof of conceptEPSS 0%

    nadh · listmonkApr 2, 2026

  • listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user

    MediumCVSS 6.5WeaponizedEPSS 2%

    nadh · listmonkJun 9, 2025

  • Listmonk v4.1.0 (fixed in v5.0.0) is vulnerable to SQL Injection in the QuerySubscribers function which allows attackers to escalate privile

    MediumCVSS 6.5No exploitEPSS 0%

    nadh · listmonkJun 4, 2025

  • listmonk: Broken Access Control in CSV Import (Unauthorized List Assignment)

    MediumCVSS 5.4No exploitEPSS 0%

    nadh · listmonkApr 2, 2026

  • listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover

    MediumCVSS 5.4No exploitEPSS 0%

    nadh · listmonkJan 2, 2026