Vulnerability index

Browse CVEs

15 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Phplist CRITICAL 9.8
CVE-2017-20029EPSS 20%

A vulnerability was found in PHPList 3.2.6 and classified as critical. This issue affects some unknown processing of the file /lists/index.php of the…

No fix yet
Fix from $2,300 2022-06-10
Phplist CRITICAL 9.8
CVE-2017-20032

A vulnerability was found in PHPList 3.2.6. It has been rated as critical. Affected by this issue is some unknown functionality of the component Subs…

No fix yet
Fix from $2,300 2022-06-10
Phplist HIGH 7.2
CVE-2017-20030

A vulnerability was found in PHPList 3.2.6. It has been classified as critical. Affected is an unknown function of the file /lists/admin/ of the comp…

No fix yet
Fix from $1,950 2022-06-10
Phplist MEDIUM 6.1
CVE-2017-20033

A vulnerability classified as problematic has been found in PHPList 3.2.6. This affects an unknown part of the file /lists/admin/. The manipulation o…

No fix yet
Fix from $1,600 2022-06-10
Phplist MEDIUM 5.4
CVE-2017-20034

A vulnerability classified as problematic was found in PHPList 3.2.6. This vulnerability affects unknown code of the file /lists/admin/ of the compon…

No fix yet
Fix from $1,600 2022-06-10
Phplist MEDIUM 5.4
CVE-2017-20035

A vulnerability, which was classified as problematic, has been found in PHPList 3.2.6. This issue affects some unknown processing of the file /lists/…

No fix yet
Fix from $1,600 2022-06-10
Phplist MEDIUM 5.4
CVE-2017-20036

A vulnerability, which was classified as problematic, was found in PHPList 3.2.6. Affected is an unknown function of the file /lists/admin/ of the co…

No fix yet
Fix from $1,600 2022-06-10
Phplist CRITICAL 9.8
CVE-2020-22249

Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the plugin zip file, Uploading a m…

No fix yet
Fix from $2,300 2021-07-06
Phplist MEDIUM 5.4
CVE-2020-23209

A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload en…

No fix yet
Fix from $1,600 2021-07-01
Phplist MEDIUM 5.4
CVE-2020-23217

A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload en…

No fix yet
Fix from $1,600 2021-07-01
Phplist CRITICAL 9.8
CVE-2020-23361

phpList 3.5.3 allows type juggling for login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e…

No fix yet
Fix from $2,300 2021-01-27
Phplist CRITICAL 9.8
CVE-2021-3188

phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.

No fix yet
Fix from $2,300 2021-01-26
Phplist HIGH 7.2
CVE-2020-35708

phpList 3.5.9 allows SQL injection by admins who provide a crafted fourth line of a file to the "Config - Import Administrators" page.

No fix yet
Fix from $1,950 2020-12-25
Phplist CRITICAL 9.8
CVE-2020-8547EPSS 6%

phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes that begin w…

No fix yet
Fix from $2,300 2020-02-03
Phplist MEDIUM 6.8
CVE-2006-5524

Cross-site scripting (XSS) vulnerability in index.php in phplist 2.10.2 allows remote attackers to inject arbitrary web script or HTML via the p para…

No fix yet
Fix from $1,600 2006-10-26