PT-2026-94080 · Phplist+1 · Phplist+1

·

CVE-2026-92806

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions phpList versions prior to 3.6.17
Description The mass subscriber removal form handler fails to validate cross-site request forgery (CSRF) tokens. CSRF is a type of attack that tricks a victim into submitting a malicious request. This allows attackers to induce logged-in administrators to visit crafted pages that silently delete and blacklist arbitrary subscriber addresses without authentication verification.
Recommendations Update to version 3.6.17 or later.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92806

Affected Products

Phplist
Phplist3