Cross-Site Request Forgery Vulnerability in phpList by phpList Ltd.
CVE-2026-92806
Key Information:
Badges
What is CVE-2026-92806?
Prior to version 3.6.17, phpList's mass subscriber removal form handler lacks sufficient validation for cross-site request forgery (CSRF) tokens. This flaw can be exploited by attackers who can manipulate authenticated administrators into visiting harmful websites. These crafted pages are designed to execute silent but unauthorized actions, such as deleting and blacklisting subscriber addresses without proper authentication checks, potentially compromising user data and administrative controls.
Affected Version(s)
phpList 0 < 3.6.17
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
