Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-92806

HIGH NVD
CVSS Score 8.1
Severity HIGH
Published Sep 16, 2026
Vendor unknown

Description

phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber removal form handler. Attackers can induce logged-in administrators to visit crafted pages that silently delete and blacklist arbitrary subscriber addresses without authentication verification.

References