Description
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Add a list" field under the "Import Emails" module.
Remediation
References
Related Vulnerabilities
MySQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-6662)
Atlassian Confluence CVE-2023-22505 Vulnerability (CVE-2023-22505)
Next.js Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVE-2026-45109)
WordPress Plugin Advanced Custom Fields:reCAPTCHA Field Security Bypass (1.1.1)