HIGH
phpList
CVE published 2026-09-16
CVE-2026-92806
phpList versions before 3.6.17 have a cross-site request forgery vulnerability in the mass subscriber removal form handler. This allows attackers to induce logged-in administrators to visit crafted pages that silently delete and blacklist arbitrary subscriber addresses without authentication verification. The vulnerability requires verification and remediation efforts from administrators and security team [truncated]