İçeriğe atla
Noroxi

phplist kayıtları

phplist üreticisine ait 41 yayımlanmış kayıt.

Tüm kayıtlar

41 kayıt
  • CVE-2017-20029
    45Planlayın

    PHPList Edit Subscription index.php sql injection

    KritikCVSS 9,8İstismar yokEPSS %21

    phplist · phplist10 Haz 2022

  • CVE-2020-8547
    41Planlayın

    phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes tha

    KritikCVSS 9,8Kavram kanıtıEPSS %6

    phplist · phplist3 Şub 2020

  • CVE-2020-22249
    40Planlayın

    Remote Code Execution vulnerability in phplist 3.5.1.

    KritikCVSS 9,8İstismar yokEPSS %3

    phplist · phplist6 Tem 2021

  • CVE-2021-3188
    40Planlayın

    phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.

    KritikCVSS 9,8İstismar yokEPSS %2

    phplist · phplist26 Oca 2021

  • CVE-2020-23361
    39İzleyin

    phpList 3.5.3 allows type juggling for login bypass because == is used instead of === for password hashes, which mishandles hashes that begi

    KritikCVSS 9,8İstismar yokEPSS %1

    phplist · phplist27 Oca 2021

  • CVE-2017-20032
    39İzleyin

    PHPList Subscription sql injection

    KritikCVSS 9,8İstismar yokEPSS %1

    phplist · phplist10 Haz 2022

  • CVE-2020-15072
    35İzleyin

    An issue was discovered in phpList through 3.5.4.

    YüksekCVSS 8,8İstismar yokEPSS %1

    phplist · phplist8 Tem 2020

  • CVE-2008-6178
    32İzleyin

    Unrestricted file upload vulnerability in editor/filemanager/browser/default/connectors/php/connector.php in FCKeditor 2.2, as used in Falt4

    YüksekCVSS 7,5Kavram kanıtıEPSS %8

    fckeditor · fckeditor19 Şub 2009

  • CVE-2012-2740
    31İzleyin

    SQL injection vulnerability in public_html/lists/admin in phpList before 2.10.18 allows remote attackers to execute arbitrary SQL commands v

    YüksekCVSS 7,5Kavram kanıtıEPSS %3

    phplist · phplist6 Eyl 2012

  • CVE-2012-3953
    30İzleyin

    SQL injection vulnerability in admin/index.php in phpList before 2.10.19 allows remote administrators to execute arbitrary SQL commands via

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    phplist · phplist11 Ağu 2012

  • CVE-2006-5524
    28İzleyin

    Cross-site scripting (XSS) vulnerability in index.php in phplist 2.10.2 allows remote attackers to inject arbitrary web script or HTML via t

    OrtaCVSS 6,8Kavram kanıtıEPSS %2

    phplist · phplist26 Eki 2006

  • CVE-2020-35708
    28İzleyin

    phpList 3.5.9 allows SQL injection by admins who provide a crafted fourth line of a file to the "Config - Import Administrators" page.

    YüksekCVSS 7,2İstismar yokEPSS %1

    phplist · phplist25 Ara 2020

  • CVE-2017-20030
    28İzleyin

    PHPList Sending Campain sql injection

    YüksekCVSS 7,2İstismar yokEPSS %1

    phplist · phplist10 Haz 2022

  • CVE-2014-2916
    27İzleyin

    Cross-site request forgery (CSRF) vulnerability in the subscription page editor (spageedit) in phpList before 3.0.6 allows remote attackers

    OrtaCVSS 6,8İstismar yokEPSS %1

    phplist · phplist5 May 2014

  • CVE-2023-27576
    26İzleyin

    An issue was discovered in phpList before 3.6.14.

    OrtaCVSS 6,7İstismar yokEPSS %0

    phplist · phplist18 Ağu 2023

  • CVE-2020-13827
    24İzleyin

    phpList before 3.5.4 allows XSS via /lists/admin/user.php and /lists/admin/users.php.

    OrtaCVSS 6,1İstismar yokEPSS %1

    phplist · phplist4 Haz 2020

  • CVE-2017-20033
    24İzleyin

    PHPList Reflected cross site scriting

    OrtaCVSS 6,1İstismar yokEPSS %1

    phplist · phplist10 Haz 2022

  • CVE-2020-12639
    24İzleyin

    phpList before 3.5.3 allows XSS, with resultant privilege elevation, via lists/admin/template.php.

    OrtaCVSS 6,1İstismar yokEPSS %1

    phplist · phplist4 May 2020

  • CVE-2025-28073
    24İzleyin

    phpList before 3.6.15 is vulnerable to Reflected Cross-Site Scripting (XSS) via the /lists/dl.php endpoint.

    OrtaCVSS 6,1Kavram kanıtıEPSS %1

    phplist · phplist8 May 2025

  • CVE-2025-28074
    24İzleyin

    phpList before 3.6.15 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php.

    OrtaCVSS 6,1Kavram kanıtıEPSS %1

    phplist · phplist8 May 2025

  • CVE-2020-15073
    21İzleyin

    An issue was discovered in phpList through 3.5.4.

    OrtaCVSS 5,4İstismar yokEPSS %1

    phplist · phplist8 Tem 2020

  • CVE-2017-20034
    21İzleyin

    PHPList List Name Persistent cross site scriting

    OrtaCVSS 5,4İstismar yokEPSS %1

    phplist · phplist10 Haz 2022

  • CVE-2017-20035
    21İzleyin

    PHPList Subscribe Persistent cross site scriting

    OrtaCVSS 5,4İstismar yokEPSS %1

    phplist · phplist10 Haz 2022

  • CVE-2017-20036
    21İzleyin

    PHPList Bounce Rule Persistent cross site scriting

    OrtaCVSS 5,4İstismar yokEPSS %1

    phplist · phplist10 Haz 2022

  • CVE-2020-23217
    21İzleyin

    A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted p

    OrtaCVSS 5,4İstismar yokEPSS %1

    phplist · phplist1 Tem 2021