{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/phplist--3.6.17/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:phplist:phplist:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-92806"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["phpList (\u003c 3.6.17)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","csrf","patch-management"],"_cs_type":"advisory","_cs_vendors":["phpList"],"content_html":"\u003cp\u003ephpList versions before 3.6.17 contain a vulnerability in the mass subscriber removal form handler, where the application fails to properly validate cross-site request forgery (CSRF) tokens. This security flaw enables a remote, unauthenticated attacker to induce an already logged-in administrator to perform unauthorized actions by visiting a specially crafted malicious webpage. Upon the administrator's interaction with this page, the application processes the removal and blacklisting of arbitrary subscriber addresses silently and without further authentication or validation prompts. This issue poses a significant risk to subscriber list integrity, potentially resulting in mass data loss or administrative disruption within marketing campaigns. Organizations utilizing affected versions of phpList should prioritize upgrading to version 3.6.17 or later to address the missing token validation mechanism.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the unauthorized deletion and permanent blacklisting of subscriber records. This can lead to the loss of entire mailing list segments, disruption of legitimate marketing activities, and administrative burden to recover subscriber data. The vulnerability is particularly severe for organizations relying on phpList for time-sensitive or critical communication.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of phpList to version 3.6.17 or later immediately to patch CVE-2026-92806.\u003c/li\u003e\n\u003cli\u003eAudit access logs for suspicious administrative activity occurring during off-hours or from anomalous IP addresses to identify potential prior abuse.\u003c/li\u003e\n\u003cli\u003eImplement strict Content Security Policy (CSP) headers on administrative dashboards to mitigate the impact of malicious cross-site scripting or redirection attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T21:58:06Z","date_published":"2026-09-16T21:58:06Z","id":"https://feed.craftedsignal.io/briefs/2026-09-phplist-csrf/","summary":"phpList versions prior to 3.6.17 are vulnerable to CSRF, allowing an attacker to force an authenticated administrator to delete or blacklist subscribers without authorization.","title":"CSRF Vulnerability in phpList Mass Subscriber Removal","url":"https://feed.craftedsignal.io/briefs/2026-09-phplist-csrf/"}],"language":"en","title":"CraftedSignal Threat Feed - PhpList (\u003c 3.6.17)","version":"https://jsonfeed.org/version/1.1"}