This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
STACKFLAG
stackflag.bsky.social
did:plc:zhe53h7ajlloep2oso5pqxzj
CVE-2026-92806 - phplist
In phpList versions earlier than 3.6.17, the page that removes multiple subscribers does not check that the request really comes from the admin’s own session. A tricked administrator who…
Too many irrelevant or confusing CVEs? Use stackflag.com
#phplist #CVE #infosec
https://stackflag.com/vulnerabilities/cve-2026-92806-phplist?utm_source=bluesky&utm_medium=social&utm_campaign=cve_poster&utm_content=cve-2026-92806
2026-09-19T04:50:05.360Z