๐Ÿ” CVE Alert

CVE-2026-92806

HIGH 8.1

phpList before 3.6.17 Cross-Site Request Forgery via massremove.php

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber removal form handler. Attackers can induce logged-in administrators to visit crafted pages that silently delete and blacklist arbitrary subscriber addresses without authentication verification.

CWE CWE-352
Vendor phplist
Product phplist
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for phplist phplist

Be the first to know when new high vulnerabilities affecting phplist phplist are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High

Affected Versions

phpList / phpList
0 < 3.6.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/geo-chen/oss/blob/main/phplist3.md github.com: https://github.com/phpList/phplist3/blob/v3.6.16/public_html/lists/admin/massremove.php#L13-L24 github.com: https://github.com/phpList/phplist3/blob/v3.6.17/public_html/lists/admin/massremove.php#L10 github.com: https://github.com/phpList/phplist3 vulncheck.com: https://www.vulncheck.com/advisories/phplist-before-3.6.17-cross-site-request-forgery-via-massremove-php

Credits

George Chen