CVE-2026-73482

phpList < 3.7.0-RC5 Cross-Site Request Forgery via admins.php

phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The administrator deletion action is triggered via an unauthenticated GET request (?page=admins&delete=N) that is not protected by a CSRF token (the central verifyCsrfGetToken check uses enforce=false and is bypassed when the token parameter is absent). A remote attacker can trick a logged-in super-administrator into loading a crafted URL (e.g., embedded as an image in an email) to delete any non-self administrator account.


We have discovered 1,198 live websites that are affected by CVE-2026-73482.

Run a Free Instant Scan




Affected Software

Product  phpList
Category Email Marketing
Vulnerable Domains1,198 live websites (100% of phpList install base)
Vulnerable Versions
  • from 0 through 3.7
Vulnerable Versions Count64 versions ( 100% of all versions)



Details

  • Published - Aug 13, 2026
  • Updated - Aug 18, 2026

Credits

  • George Chen (finder)

Website Distribution by Country

Number of websites using CVE-2026-73482
United States229 websites



Singapore262 websites
Germany195 websites
France79 websites
Italy65 websites
GB43 websites
Portugal32 websites
Canada30 websites
Netherlands25 websites
Spain23 websites

Website Distribution by TLD

Number of websites using CVE-2026-73482
.com537 websites
.de113 websites
.org104 websites
.it49 websites
.net38 websites
.fr27 websites
.co.uk21 websites
.at17 websites
.ch15 websites
.nl15 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-73482

Top websites that are affected by CVE-2026-73482. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.net United States**,***
*******.com United States***,***
******.com United States***,***
*******.com United States***,***
*******.com United States***,***
*****.org Israel***,***
*****.com United States***,***
***.**.jp Japan***,***
**********.com United States***,***
**********.com United States***,***
See full domain list

FAQ

A total of 1,198 websites have been identified as vulnerable to CVE-2026-73482, based on global website indexing conducted by WebTechSurvey.
The phpList is affected by the CVE-2026-73482 vulnerability.
phpList versions up to 3.7 are vulnerable to CVE-2026-73482.
CVE-2026-73482 is resolved in version 3.7 of phpList.