CVE-2026-73481

phpList < 3.7.0-RC5 Cross-Site Request Forgery via Bounce Rules

phpList before 3.7.0-RC5 fail to enforce CSRF token validation on the bounce rule deletion endpoint (bouncerules.php / bouncerule.php). The deletion is performed via a GET request (?page=bouncerules&del=N), and the central CSRF check (verifyCsrfGetToken) is invoked with enforce=false, so it only validates the token when a 'tk' parameter is present. A remote attacker can trick an authenticated administrator into loading a crafted URL (e.g., embedded in an image tag) to delete arbitrary bounce rules from the phplist_bounceregex table without a valid CSRF token.


We have discovered 1,198 live websites that are affected by CVE-2026-73481.

Run a Free Instant Scan




Affected Software

Product  phpList
Category Email Marketing
Vulnerable Domains1,198 live websites (100% of phpList install base)
Vulnerable Versions
  • from 0 through 3.7
Vulnerable Versions Count64 versions ( 100% of all versions)



Details

  • Published - Aug 13, 2026
  • Updated - Aug 14, 2026

Credits

  • George Chen (finder)

Website Distribution by Country

Number of websites using CVE-2026-73481
United States229 websites



Singapore262 websites
Germany195 websites
France79 websites
Italy65 websites
GB43 websites
Portugal32 websites
Canada30 websites
Netherlands25 websites
Spain23 websites

Website Distribution by TLD

Number of websites using CVE-2026-73481
.com537 websites
.de113 websites
.org104 websites
.it49 websites
.net38 websites
.fr27 websites
.co.uk21 websites
.at17 websites
.ch15 websites
.nl15 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-73481

Top websites that are affected by CVE-2026-73481. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.net United States**,***
*******.com United States***,***
******.com United States***,***
*******.com United States***,***
*******.com United States***,***
*****.org Israel***,***
*****.com United States***,***
***.**.jp Japan***,***
**********.com United States***,***
**********.com United States***,***
See full domain list

FAQ

A total of 1,198 websites have been identified as vulnerable to CVE-2026-73481, based on global website indexing conducted by WebTechSurvey.
The phpList is affected by the CVE-2026-73481 vulnerability.
phpList versions up to 3.7 are vulnerable to CVE-2026-73481.
CVE-2026-73481 is resolved in version 3.7 of phpList.