Search Results (44 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-15073 1 Phplist 1 Phplist 2024-11-21 5.4 Medium
An issue was discovered in phpList through 3.5.4. An XSS vulnerability occurs within the Import Administrators section via upload of an edited text document. This also affects the Subscriber Lists section.
CVE-2020-15072 1 Phplist 1 Phplist 2024-11-21 8.8 High
An issue was discovered in phpList through 3.5.4. An error-based SQL Injection vulnerability exists via the Import Administrators section.
CVE-2020-13827 1 Phplist 1 Phplist 2024-11-21 6.1 Medium
phpList before 3.5.4 allows XSS via /lists/admin/user.php and /lists/admin/users.php.
CVE-2020-12639 1 Phplist 1 Phplist 2024-11-21 6.1 Medium
phpList before 3.5.3 allows XSS, with resultant privilege elevation, via lists/admin/template.php.