Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phplist vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2020-8547
phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.
Phplist Phplist 3.5.0
9.8
CVSSv3
CVE-2020-22249
Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the plugin zip file, Uploading a malicious plugin which contains the php files with extensions like PHP,phtml,php7 will be copied to the plugins directory which woul...
Phplist Phplist 3.5.1
5.4
CVSSv3
CVE-2020-23190
A stored cross site scripting (XSS) vulnerability in the "Import emails" module in phplist 3.5.4 allows authenticated malicious users to execute arbitrary web scripts or HTML via a crafted payload.
Phplist Phplist 3.5.4
5.4
CVSSv3
CVE-2020-23207
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload entered into the "Edit Values" field under the "Configure Attributes" module.
Phplist Phplist 3.5.3
5.4
CVSSv3
CVE-2020-23209
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload entered into the "List Description" field under the "Edit A List" module.
Phplist Phplist 3.5.3
5.4
CVSSv3
CVE-2020-23214
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload entered into the "Configure categories" field under the "Categorise Lists" module.
Phplist Phplist 3.5.3
9.8
CVSSv3
CVE-2020-23361
phpList 3.5.3 allows type juggling for login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.
Phplist Phplist 3.5.3
NA
CVE-2015-3345
SQL injection vulnerability in the PHPlist Integration Module prior to 6.x-1.7 for Drupal allows remote administrators to execute arbitrary SQL commands via unspecified vectors, related to the "phpList database."
Phplist Integration Project Phplist Integration
NA
CVE-2009-4066
Multiple cross-site request forgery (CSRF) vulnerabilities in the "My Account" feature in PHPList Integration module 5 prior to 5.x-1.2 and 6 prior to 6.x-1.1 for Drupal allow remote malicious users to hijack the authentication of arbitrary users via vectors related to ...
Drupal Drupal
Paul Beaney Phplist 5.x-1.x
Paul Beaney Phplist 6.x-1.x
Paul Beaney Phplist 6.x-1.0
Paul Beaney Phplist 5.x-1.0
Paul Beaney Phplist 5.x-1.1
NA
CVE-2005-2432
SQL injection vulnerability in PhpList allows remote malicious users to modify SQL statements via the id argument to admin pages such as (1) members or (2) admin.
Tincan Phplist
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
remote code execution
CVE-2024-34909
CVE-2024-3317
SSTI
CVE-2024-3400
CVE-2024-30051
wireless
CVE-2024-4622
CVE-2024-4908
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »