PatchSiren

phpList CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH phpList CVE published 2026-09-16

CVE-2026-92806

phpList versions before 3.6.17 have a cross-site request forgery vulnerability in the mass subscriber removal form handler. This allows attackers to induce logged-in administrators to visit crafted pages that silently delete and blacklist arbitrary subscriber addresses without authentication verification. The vulnerability requires verification and remediation efforts from administrators and security team [truncated]