Vulnerability index

Browse CVEs

34 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Phplist MEDIUM 6.1
CVE-2025-28074

phpList before 3.6.15 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php. The vulnerability is exploitable when…

Fix: 3.6.15+
Fix from $1,600 2025-05-08
Phplist MEDIUM 6.1
CVE-2025-28073

phpList before 3.6.15 is vulnerable to Reflected Cross-Site Scripting (XSS) via the /lists/dl.php endpoint. An attacker can inject arbitrary JavaScri…

Fix: 3.6.15+
Fix from $1,600 2025-05-08
Phplist MEDIUM 6.7
CVE-2023-27576

An issue was discovered in phpList before 3.6.14. Due to an access error, it was possible to manipulate and edit data of the system's super admin, al…

Patch available
Fix from $1,600 2023-08-18
Phplist CRITICAL 9.8
CVE-2017-20029EPSS 20%

A vulnerability was found in PHPList 3.2.6 and classified as critical. This issue affects some unknown processing of the file /lists/index.php of the…

No fix yet
Fix from $2,300 2022-06-10
Phplist CRITICAL 9.8
CVE-2017-20032

A vulnerability was found in PHPList 3.2.6. It has been rated as critical. Affected by this issue is some unknown functionality of the component Subs…

No fix yet
Fix from $2,300 2022-06-10
Phplist HIGH 7.2
CVE-2017-20030

A vulnerability was found in PHPList 3.2.6. It has been classified as critical. Affected is an unknown function of the file /lists/admin/ of the comp…

No fix yet
Fix from $1,950 2022-06-10
Phplist MEDIUM 6.1
CVE-2017-20033

A vulnerability classified as problematic has been found in PHPList 3.2.6. This affects an unknown part of the file /lists/admin/. The manipulation o…

No fix yet
Fix from $1,600 2022-06-10
Phplist MEDIUM 5.4
CVE-2017-20034

A vulnerability classified as problematic was found in PHPList 3.2.6. This vulnerability affects unknown code of the file /lists/admin/ of the compon…

No fix yet
Fix from $1,600 2022-06-10
Phplist MEDIUM 5.4
CVE-2017-20035

A vulnerability, which was classified as problematic, has been found in PHPList 3.2.6. This issue affects some unknown processing of the file /lists/…

No fix yet
Fix from $1,600 2022-06-10
Phplist MEDIUM 5.4
CVE-2017-20036

A vulnerability, which was classified as problematic, was found in PHPList 3.2.6. Affected is an unknown function of the file /lists/admin/ of the co…

No fix yet
Fix from $1,600 2022-06-10
Phplist CRITICAL 9.8
CVE-2020-22249

Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the plugin zip file, Uploading a m…

No fix yet
Fix from $2,300 2021-07-06
Phplist MEDIUM 5.4
CVE-2020-23190

A stored cross site scripting (XSS) vulnerability in the "Import emails" module in phplist 3.5.4 allows authenticated attackers to execute arbitrary …

Patch available
Fix from $1,600 2021-07-02
Phplist MEDIUM 5.4
CVE-2020-23192

A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows authenticated attackers to execute arbitrary web scripts or HTML …

Fix: after 3.5.4
Fix from $1,600 2021-07-02
Phplist MEDIUM 5.4
CVE-2020-23194

A stored cross site scripting (XSS) vulnerability in the "Import Subscribers" feature in phplist 3.5.4 and below allows authenticated attackers to ex…

Fix: after 3.5.4
Fix from $1,600 2021-07-02
Phplist MEDIUM 5.4
CVE-2020-36398

A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows attackers to execute arbitrary web scripts or HTML via a crafted …

Fix: after 3.5.4
Fix from $1,600 2021-07-02
Phplist MEDIUM 5.4
CVE-2020-36399

A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows attackers to execute arbitrary web scripts or HTML via a crafted …

Fix: after 3.5.4
Fix from $1,600 2021-07-02
Phplist MEDIUM 5.4
CVE-2020-23207

A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload en…

Patch available
Fix from $1,600 2021-07-01
Phplist MEDIUM 5.4
CVE-2020-23208

A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload en…

Patch available
Fix from $1,600 2021-07-01
Phplist MEDIUM 5.4
CVE-2020-23209

A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload en…

No fix yet
Fix from $1,600 2021-07-01
Phplist MEDIUM 5.4
CVE-2020-23214

A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload en…

Patch available
Fix from $1,600 2021-07-01
Phplist MEDIUM 5.4
CVE-2020-23217

A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload en…

No fix yet
Fix from $1,600 2021-07-01
Phplist CRITICAL 9.8
CVE-2020-23361

phpList 3.5.3 allows type juggling for login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e…

No fix yet
Fix from $2,300 2021-01-27
Phplist CRITICAL 9.8
CVE-2021-3188

phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.

No fix yet
Fix from $2,300 2021-01-26
Phplist HIGH 7.2
CVE-2020-35708

phpList 3.5.9 allows SQL injection by admins who provide a crafted fourth line of a file to the "Config - Import Administrators" page.

No fix yet
Fix from $1,950 2020-12-25
Phplist HIGH 8.8
CVE-2020-15072

An issue was discovered in phpList through 3.5.4. An error-based SQL Injection vulnerability exists via the Import Administrators section.

Fix: after 3.5.4
Fix from $1,950 2020-07-08
Phplist MEDIUM 5.4
CVE-2020-15073

An issue was discovered in phpList through 3.5.4. An XSS vulnerability occurs within the Import Administrators section via upload of an edited text d…

Fix: after 3.5.4
Fix from $1,600 2020-07-08
Phplist MEDIUM 6.1
CVE-2020-13827

phpList before 3.5.4 allows XSS via /lists/admin/user.php and /lists/admin/users.php.

Fix: 3.5.4+
Fix from $1,600 2020-06-04
Phplist MEDIUM 6.1
CVE-2020-12639

phpList before 3.5.3 allows XSS, with resultant privilege elevation, via lists/admin/template.php.

Fix: 3.5.3+
Fix from $1,600 2020-05-04
Phplist CRITICAL 9.8
CVE-2020-8547EPSS 6%

phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes that begin w…

No fix yet
Fix from $2,300 2020-02-03
Phplist MEDIUM 6.8
CVE-2014-2916

Cross-site request forgery (CSRF) vulnerability in the subscription page editor (spageedit) in phpList before 3.0.6 allows remote attackers to hijack…

Fix: after 3.0.5
Fix from $1,600 2014-05-05