Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phplist phplist 3.5.4 vulnerabilities and exploits
(subscribe to this query)
3.5
CVSSv2
CVE-2020-23190
A stored cross site scripting (XSS) vulnerability in the "Import emails" module in phplist 3.5.4 allows authenticated malicious users to execute arbitrary web scripts or HTML via a crafted payload.
Phplist Phplist 3.5.4
4.3
CVSSv2
CVE-2020-13827
phpList prior to 3.5.4 allows XSS via /lists/admin/user.php and /lists/admin/users.php.
Phplist Phplist
6.5
CVSSv2
CVE-2020-15072
An issue exists in phpList up to and including 3.5.4. An error-based SQL Injection vulnerability exists via the Import Administrators section.
Phplist Phplist
3.5
CVSSv2
CVE-2020-23194
A stored cross site scripting (XSS) vulnerability in the "Import Subscribers" feature in phplist 3.5.4 and below allows authenticated malicious users to execute arbitrary web scripts or HTML via a crafted payload.
Phplist Phplist
3.5
CVSSv2
CVE-2020-15073
An issue exists in phpList up to and including 3.5.4. An XSS vulnerability occurs within the Import Administrators section via upload of an edited text document. This also affects the Subscriber Lists section.
Phplist Phplist
3.5
CVSSv2
CVE-2020-36399
A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows malicious users to execute arbitrary web scripts or HTML via a crafted payload in the "rule1" parameter under the "Bounce Rules" module.
Phplist Phplist
3.5
CVSSv2
CVE-2020-23192
A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows authenticated malicious users to execute arbitrary web scripts or HTML via a crafted payload in the "admin" parameter under the "Manage administrators" module.
Phplist Phplist
3.5
CVSSv2
CVE-2020-36398
A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows malicious users to execute arbitrary web scripts or HTML via a crafted payload in the "Campaign" field under the "Send a campaign" module.
Phplist Phplist
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-32976
CVE-2024-33557
CVE-2024-36801
CVE-2024-35654
authentication bypass
CVE-2024-24919
CSRF
code execution
CVE-2024-27348
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started