Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14044 | phpList before 3.6.15 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php. The vulnerability is exploitable when the application dynamically references internal paths and processes untrusted input without escaping, allowing an attacker to inject malicious JavaScript. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 16 Jun 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Phplist
Phplist phplist |
|
| CPEs | cpe:2.3:a:phplist:phplist:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Phplist
Phplist phplist |
Sat, 07 Jun 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | phpList prior to 3.6.3 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php. The vulnerability is exploitable when the application dynamically references internal paths and processes untrusted input without escaping, allowing an attacker to inject malicious JavaScript. | phpList before 3.6.15 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php. The vulnerability is exploitable when the application dynamically references internal paths and processes untrusted input without escaping, allowing an attacker to inject malicious JavaScript. |
| References |
|
Mon, 12 May 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Thu, 08 May 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | phpList prior to 3.6.3 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php. The vulnerability is exploitable when the application dynamically references internal paths and processes untrusted input without escaping, allowing an attacker to inject malicious JavaScript. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-06-07T14:42:05.947Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-28074
Updated: 2025-05-12T22:05:51.272Z
Status : Analyzed
Published: 2025-05-08T21:15:50.200
Modified: 2025-06-16T18:39:00.380
Link: CVE-2025-28074
No data.
OpenCVE Enrichment
No data.
EUVD