Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phplist vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2020-36399
A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows malicious users to execute arbitrary web scripts or HTML via a crafted payload in the "rule1" parameter under the "Bounce Rules" module.
Phplist Phplist
6.1
CVSSv3
CVE-2020-12639
phpList prior to 3.5.3 allows XSS, with resultant privilege elevation, via lists/admin/template.php.
Phplist Phplist
8.8
CVSSv3
CVE-2020-15072
An issue exists in phpList up to and including 3.5.4. An error-based SQL Injection vulnerability exists via the Import Administrators section.
Phplist Phplist
6.1
CVSSv3
CVE-2020-13827
phpList prior to 3.5.4 allows XSS via /lists/admin/user.php and /lists/admin/users.php.
Phplist Phplist
5.4
CVSSv3
CVE-2020-23192
A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows authenticated malicious users to execute arbitrary web scripts or HTML via a crafted payload in the "admin" parameter under the "Manage administrators" module.
Phplist Phplist
5.4
CVSSv3
CVE-2020-23194
A stored cross site scripting (XSS) vulnerability in the "Import Subscribers" feature in phplist 3.5.4 and below allows authenticated malicious users to execute arbitrary web scripts or HTML via a crafted payload.
Phplist Phplist
6.7
CVSSv3
CVE-2023-27576
An issue exists in phpList prior to 3.6.14. Due to an access error, it was possible to manipulate and edit data of the system's super admin, allowing one to perform an account takeover of the user with super-admin permission. Specifically, for a request with updatepassword=1...
Phplist Phplist 3.6.12
NA
CVE-2006-5524
Cross-site scripting (XSS) vulnerability in index.php in phplist 2.10.2 allows remote malicious users to inject arbitrary web script or HTML via the p parameter. NOTE: This issue might overlap CVE-2006-5321.
Phplist Phplist 2.10.2
1 EDB exploit
7.2
CVSSv3
CVE-2020-35708
phpList 3.5.9 allows SQL injection by admins who provide a crafted fourth line of a file to the "Config - Import Administrators" page.
Phplist Phplist 3.5.9
9.8
CVSSv3
CVE-2020-22249
Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the plugin zip file, Uploading a malicious plugin which contains the php files with extensions like PHP,phtml,php7 will be copied to the plugins directory which woul...
Phplist Phplist 3.5.1
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3581
reflected XSS
CVE-2024-26925
CVE-2024-27956
LFI
CVE-2024-3607
CVE-2024-3107
CVE-2024-3295
SQL
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »