CVE-2020-12639
phpList before 3.5.3 allows XSS, with resultant privilege elevation, via lists/admin/template.php.
Date published : 2020-05-04
https://github.com/phpList/phplist3/compare/3.5.2…3.5.3
phpList 3.5.3 released: Enable Matomo Analytics for your campaigns