phpList before 3.7.0-RC5 fail to enforce CSRF token validation on the bounce rule deletion endpoint (bouncerules.php / bouncerule.php). The deletion is performed via a GET request (?page=bouncerules&del=N), and the central CSRF check (verifyCsrfGetToken) is invoked with enforce=false, so it only validates the token when a 'tk' parameter is present. A remote attacker can trick an authenticated administrator into loading a crafted URL (e.g., embedded in an image tag) to delete arbitrary bounce rules from the phplist_bounceregex table without a valid CSRF token.
We have discovered 1,198 live websites that are affected by CVE-2026-73481.
| Product | |
| Category | Email Marketing |
| Vulnerable Domains | 1,198 live websites (100% of phpList install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 64 versions ( 100% of all versions) |
| 229 websites | |
| 262 websites | |
| 195 websites | |
| 79 websites | |
| 65 websites | |
| 43 websites | |
| 32 websites | |
| 30 websites | |
| 25 websites | |
| 23 websites |
| .com | 537 websites |
| .de | 113 websites |
| .org | 104 websites |
| .it | 49 websites |
| .net | 38 websites |
| .fr | 27 websites |
| .co.uk | 21 websites |
| .at | 17 websites |
| .ch | 15 websites |
| .nl | 15 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.net | **,*** | ||
| *******.com | ***,*** | ||
| ******.com | ***,*** | ||
| *******.com | ***,*** | ||
| *******.com | ***,*** | ||
| *****.org | ***,*** | ||
| *****.com | ***,*** | ||
| ***.**.jp | ***,*** | ||
| **********.com | ***,*** | ||
| **********.com | ***,*** |
FAQ