phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The administrator deletion action is triggered via an unauthenticated GET request (?page=admins&delete=N) that is not protected by a CSRF token (the central verifyCsrfGetToken check uses enforce=false and is bypassed when the token parameter is absent). A remote attacker can trick a logged-in super-administrator into loading a crafted URL (e.g., embedded as an image in an email) to delete any non-self administrator account.
We have discovered 1,198 live websites that are affected by CVE-2026-73482.
| Product | |
| Category | Email Marketing |
| Vulnerable Domains | 1,198 live websites (100% of phpList install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 64 versions ( 100% of all versions) |
| 229 websites | |
| 262 websites | |
| 195 websites | |
| 79 websites | |
| 65 websites | |
| 43 websites | |
| 32 websites | |
| 30 websites | |
| 25 websites | |
| 23 websites |
| .com | 537 websites |
| .de | 113 websites |
| .org | 104 websites |
| .it | 49 websites |
| .net | 38 websites |
| .fr | 27 websites |
| .co.uk | 21 websites |
| .at | 17 websites |
| .ch | 15 websites |
| .nl | 15 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.net | **,*** | ||
| *******.com | ***,*** | ||
| ******.com | ***,*** | ||
| *******.com | ***,*** | ||
| *******.com | ***,*** | ||
| *****.org | ***,*** | ||
| *****.com | ***,*** | ||
| ***.**.jp | ***,*** | ||
| **********.com | ***,*** | ||
| **********.com | ***,*** |
FAQ