phplist kayıtları
phplist üreticisine ait 41 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %19,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')20
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')7
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)4
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
41 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
45Planlayın | CVE-2017-20029İstismar yok | PHPList Edit Subscription index.php sql injectionphplist · phplist · CWE-89 | Kritik9,8 | — | %21,0 | 10 Haz 2022 |
41Planlayın | CVE-2020-8547Kavram kanıtı | phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes thaphplist · phplist | Kritik9,8 | — | %5,9 | 3 Şub 2020 |
40Planlayın | CVE-2020-22249İstismar yok | Remote Code Execution vulnerability in phplist 3.5.1.phplist · phplist · CWE-434 | Kritik9,8 | — | %2,9 | 6 Tem 2021 |
40Planlayın | CVE-2021-3188İstismar yok | phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.phplist · phplist · CWE-1236 | Kritik9,8 | — | %1,8 | 26 Oca 2021 |
39İzleyin | CVE-2020-23361İstismar yok | phpList 3.5.3 allows type juggling for login bypass because == is used instead of === for password hashes, which mishandles hashes that begiphplist · phplist | Kritik9,8 | — | %1,2 | 27 Oca 2021 |
39İzleyin | CVE-2017-20032İstismar yok | PHPList Subscription sql injectionphplist · phplist · CWE-89 | Kritik9,8 | — | %1,0 | 10 Haz 2022 |
35İzleyin | CVE-2020-15072İstismar yok | An issue was discovered in phpList through 3.5.4.phplist · phplist · CWE-89 | Yüksek8,8 | — | %1,2 | 8 Tem 2020 |
32İzleyin | CVE-2008-6178Kavram kanıtı | Unrestricted file upload vulnerability in editor/filemanager/browser/default/connectors/php/connector.php in FCKeditor 2.2, as used in Falt4fckeditor · fckeditor · CWE-94 | Yüksek7,5 | — | %7,8 | 19 Şub 2009 |
31İzleyin | CVE-2012-2740Kavram kanıtı | SQL injection vulnerability in public_html/lists/admin in phpList before 2.10.18 allows remote attackers to execute arbitrary SQL commands vphplist · phplist · CWE-89 | Yüksek7,5 | — | %3,3 | 6 Eyl 2012 |
30İzleyin | CVE-2012-3953Kavram kanıtı | SQL injection vulnerability in admin/index.php in phpList before 2.10.19 allows remote administrators to execute arbitrary SQL commands via phplist · phplist · CWE-89 | Yüksek7,5 | — | %1,1 | 11 Ağu 2012 |
28İzleyin | CVE-2006-5524Kavram kanıtı | Cross-site scripting (XSS) vulnerability in index.php in phplist 2.10.2 allows remote attackers to inject arbitrary web script or HTML via tphplist · phplist | Orta6,8 | — | %2,1 | 26 Eki 2006 |
28İzleyin | CVE-2020-35708İstismar yok | phpList 3.5.9 allows SQL injection by admins who provide a crafted fourth line of a file to the "Config - Import Administrators" page.phplist · phplist · CWE-89 | Yüksek7,2 | — | %1,5 | 25 Ara 2020 |
28İzleyin | CVE-2017-20030İstismar yok | PHPList Sending Campain sql injectionphplist · phplist · CWE-89 | Yüksek7,2 | — | %0,9 | 10 Haz 2022 |
27İzleyin | CVE-2014-2916İstismar yok | Cross-site request forgery (CSRF) vulnerability in the subscription page editor (spageedit) in phpList before 3.0.6 allows remote attackers phplist · phplist · CWE-352 | Orta6,8 | — | %1,1 | 5 May 2014 |
26İzleyin | CVE-2023-27576İstismar yok | An issue was discovered in phpList before 3.6.14.phplist · phplist · CWE-639 | Orta6,7 | — | %0,3 | 18 Ağu 2023 |
24İzleyin | CVE-2020-13827İstismar yok | phpList before 3.5.4 allows XSS via /lists/admin/user.php and /lists/admin/users.php.phplist · phplist · CWE-79 | Orta6,1 | — | %0,8 | 4 Haz 2020 |
24İzleyin | CVE-2017-20033İstismar yok | PHPList Reflected cross site scritingphplist · phplist · CWE-80 | Orta6,1 | — | %0,7 | 10 Haz 2022 |
24İzleyin | CVE-2020-12639İstismar yok | phpList before 3.5.3 allows XSS, with resultant privilege elevation, via lists/admin/template.php.phplist · phplist · CWE-79 | Orta6,1 | — | %0,7 | 4 May 2020 |
24İzleyin | CVE-2025-28073Kavram kanıtı | phpList before 3.6.15 is vulnerable to Reflected Cross-Site Scripting (XSS) via the /lists/dl.php endpoint.phplist · phplist · CWE-79 | Orta6,1 | — | %0,6 | 8 May 2025 |
24İzleyin | CVE-2025-28074Kavram kanıtı | phpList before 3.6.15 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php.phplist · phplist · CWE-79 | Orta6,1 | — | %0,6 | 8 May 2025 |
21İzleyin | CVE-2020-15073İstismar yok | An issue was discovered in phpList through 3.5.4.phplist · phplist · CWE-79 | Orta5,4 | — | %0,7 | 8 Tem 2020 |
21İzleyin | CVE-2017-20034İstismar yok | PHPList List Name Persistent cross site scritingphplist · phplist · CWE-80 | Orta5,4 | — | %0,6 | 10 Haz 2022 |
21İzleyin | CVE-2017-20035İstismar yok | PHPList Subscribe Persistent cross site scritingphplist · phplist · CWE-80 | Orta5,4 | — | %0,6 | 10 Haz 2022 |
21İzleyin | CVE-2017-20036İstismar yok | PHPList Bounce Rule Persistent cross site scritingphplist · phplist · CWE-80 | Orta5,4 | — | %0,6 | 10 Haz 2022 |
21İzleyin | CVE-2020-23217İstismar yok | A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted pphplist · phplist · CWE-79 | Orta5,4 | — | %0,6 | 1 Tem 2021 |
- CVE-2017-2002945Planlayın
PHPList Edit Subscription index.php sql injection
KritikCVSS 9,8İstismar yokEPSS %21phplist · phplist10 Haz 2022
- CVE-2020-854741Planlayın
phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes tha
KritikCVSS 9,8Kavram kanıtıEPSS %6phplist · phplist3 Şub 2020
- CVE-2020-2224940Planlayın
Remote Code Execution vulnerability in phplist 3.5.1.
KritikCVSS 9,8İstismar yokEPSS %3phplist · phplist6 Tem 2021
- CVE-2021-318840Planlayın
phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.
KritikCVSS 9,8İstismar yokEPSS %2phplist · phplist26 Oca 2021
- CVE-2020-2336139İzleyin
phpList 3.5.3 allows type juggling for login bypass because == is used instead of === for password hashes, which mishandles hashes that begi
KritikCVSS 9,8İstismar yokEPSS %1phplist · phplist27 Oca 2021
- CVE-2017-2003239İzleyin
PHPList Subscription sql injection
KritikCVSS 9,8İstismar yokEPSS %1phplist · phplist10 Haz 2022
- CVE-2020-1507235İzleyin
An issue was discovered in phpList through 3.5.4.
YüksekCVSS 8,8İstismar yokEPSS %1phplist · phplist8 Tem 2020
- CVE-2008-617832İzleyin
Unrestricted file upload vulnerability in editor/filemanager/browser/default/connectors/php/connector.php in FCKeditor 2.2, as used in Falt4
YüksekCVSS 7,5Kavram kanıtıEPSS %8fckeditor · fckeditor19 Şub 2009
- CVE-2012-274031İzleyin
SQL injection vulnerability in public_html/lists/admin in phpList before 2.10.18 allows remote attackers to execute arbitrary SQL commands v
YüksekCVSS 7,5Kavram kanıtıEPSS %3phplist · phplist6 Eyl 2012
- CVE-2012-395330İzleyin
SQL injection vulnerability in admin/index.php in phpList before 2.10.19 allows remote administrators to execute arbitrary SQL commands via
YüksekCVSS 7,5Kavram kanıtıEPSS %1phplist · phplist11 Ağu 2012
- CVE-2006-552428İzleyin
Cross-site scripting (XSS) vulnerability in index.php in phplist 2.10.2 allows remote attackers to inject arbitrary web script or HTML via t
OrtaCVSS 6,8Kavram kanıtıEPSS %2phplist · phplist26 Eki 2006
- CVE-2020-3570828İzleyin
phpList 3.5.9 allows SQL injection by admins who provide a crafted fourth line of a file to the "Config - Import Administrators" page.
YüksekCVSS 7,2İstismar yokEPSS %1phplist · phplist25 Ara 2020
- CVE-2017-2003028İzleyin
PHPList Sending Campain sql injection
YüksekCVSS 7,2İstismar yokEPSS %1phplist · phplist10 Haz 2022
- CVE-2014-291627İzleyin
Cross-site request forgery (CSRF) vulnerability in the subscription page editor (spageedit) in phpList before 3.0.6 allows remote attackers
OrtaCVSS 6,8İstismar yokEPSS %1phplist · phplist5 May 2014
- CVE-2023-2757626İzleyin
An issue was discovered in phpList before 3.6.14.
OrtaCVSS 6,7İstismar yokEPSS %0phplist · phplist18 Ağu 2023
- CVE-2020-1382724İzleyin
phpList before 3.5.4 allows XSS via /lists/admin/user.php and /lists/admin/users.php.
OrtaCVSS 6,1İstismar yokEPSS %1phplist · phplist4 Haz 2020
- CVE-2017-2003324İzleyin
PHPList Reflected cross site scriting
OrtaCVSS 6,1İstismar yokEPSS %1phplist · phplist10 Haz 2022
- CVE-2020-1263924İzleyin
phpList before 3.5.3 allows XSS, with resultant privilege elevation, via lists/admin/template.php.
OrtaCVSS 6,1İstismar yokEPSS %1phplist · phplist4 May 2020
- CVE-2025-2807324İzleyin
phpList before 3.6.15 is vulnerable to Reflected Cross-Site Scripting (XSS) via the /lists/dl.php endpoint.
OrtaCVSS 6,1Kavram kanıtıEPSS %1phplist · phplist8 May 2025
- CVE-2025-2807424İzleyin
phpList before 3.6.15 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php.
OrtaCVSS 6,1Kavram kanıtıEPSS %1phplist · phplist8 May 2025
- CVE-2020-1507321İzleyin
An issue was discovered in phpList through 3.5.4.
OrtaCVSS 5,4İstismar yokEPSS %1phplist · phplist8 Tem 2020
- CVE-2017-2003421İzleyin
PHPList List Name Persistent cross site scriting
OrtaCVSS 5,4İstismar yokEPSS %1phplist · phplist10 Haz 2022
- CVE-2017-2003521İzleyin
PHPList Subscribe Persistent cross site scriting
OrtaCVSS 5,4İstismar yokEPSS %1phplist · phplist10 Haz 2022
- CVE-2017-2003621İzleyin
PHPList Bounce Rule Persistent cross site scriting
OrtaCVSS 5,4İstismar yokEPSS %1phplist · phplist10 Haz 2022
- CVE-2020-2321721İzleyin
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted p
OrtaCVSS 5,4İstismar yokEPSS %1phplist · phplist1 Tem 2021