8 Total advisories
8 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/knadh/listmonk is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CRITICAL 9.0
CVE-2025-49136
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user
UNKNOWN
CVE-2025-58430
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover
HIGH 7.1
CVE-2026-34828
listmonk's active sessions remain valid after password reset and password change
UNKNOWN
CVE-2026-34828
listmonk's active sessions remain valid after password reset and password change in github.com/knadh/listmonk
UNKNOWN
CVE-2025-58430
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover in github.com/knadh/listmonk
UNKNOWN
CVE-2026-21483
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover
UNKNOWN
CVE-2026-21483
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover in github.com/knadh/listmonk
UNKNOWN
CVE-2025-49136
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user in github.com/knadh/listmonk
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes