Home

Description

phpList before 3.6.15 is vulnerable to Reflected Cross-Site Scripting (XSS) via the /lists/dl.php endpoint. An attacker can inject arbitrary JavaScript code by manipulating the id parameter, which is improperly sanitized.

PUBLISHED Reserved 2025-03-11 | Published 2025-05-08 | Updated 2025-06-07 | Assigner mitre

References

github.com/phpList/phplist3

github.com/mLniumm/CVE-2025-28073

github.com/phpList/phplist3/compare/v3.6.14...v3.6.15

www.phplist.org/newslist/phplist-3-6-15-release-notes/

cve.org (CVE-2025-28073)

nvd.nist.gov (CVE-2025-28073)

Download JSON