phpList 3.6.6 released: security improvements, new features & translations


A new version for phpList is now ready for download, introducing several changes.

Changes included in this release:

New features:

  • Update jQuery version to the latest stable in order to be up to date and for security hardening. See pull requests #818, #90 and #122.
  • Specify the database engine option of your choice. A new configuration option has been added to allow the phpList administrator to specify their preferred database engine. See pull request #815.
  • Allow database initialization from the command line. As a phpList administrator, you will be able to initialize your database from both your phpList dashboard and the commandline. See pull requests #812 and #813.
  • Add analytics parameters for HTTP/ HTTPS URLs when click tracking is not enabled. When click tracking is enabled only HTTP/ HTTPS links are tracked. Analytic parameters are added when a link is clicked, therefore are added only to the HTTP not to “mailto:” for example. For more, see pull request #810.
  • Display subscriber list ID when viewing lists. A new field has been added to display the list’s ID when looking at the full set of subscribers lists. See pull request #811.

Fixes & improvements

Security fixes

  • CVE-2020-35708 – resolved in 3.6.0
  • CVE-2021-3188 – resolved in 3.6.3


This release is the work of @mfettig, Duncan Cameron, and other Open Source community members who have submitted Pull Requests, bug reports and valuable feedback, as well as phpList Ltd. developers. To get involved in phpList development, check out the developer resources pages.

Report any issues you find with phpList 4 core or REST API  to the corresponding repo on GitHub. Please read the contribution guide on how to contribute to these modules.


Need help upgrading your phpList server to the newest version? Ask the community at Professional support from community experts, as well as manuals, source code, and developer resources, can be found at Report all bugs to the phpList3 GitHub repository.

Want to focus on campaigns and forget hosting headaches? Sign up at for an account with everything included. Send from 300 free messages to 30 million messages per month — simple.


Leave a Reply