rootpwn

critical · CVSS v3 8.1 · CVSS v4 7.2

CVE-2026-92806

phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber removal form ha…

Description

phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber removal form handler. Attackers can induce logged-in administrators to visit crafted pages that silently delete and blacklist arbitrary subscriber addresses without authentication verification.

Scores

Severity
critical
CVSS v2
9.4
CVSS v3
8.1
CVSS v4
7.2
EPSS

← All CVEs