CVE-2026-92806
EUVD-2026-8106616.09.2026, 21:17
phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber removal form handler. Attackers can induce logged-in administrators to visit crafted pages that silently delete and blacklist arbitrary subscriber addresses without authentication verification.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| phplist | phplist | 𝑥 < 3.6.17 | CNA |
Common Weakness Enumeration
References