{"id":"CVE-2025-68951","title":"phpMyFAQ is an open source FAQ web application","summary":"phpMyFAQ is an open source FAQ web application. Versions 4.0.14 and 4.0.15 have a stored cross-site scripting (XSS) vulnerability that allows an attacker to execute arbitrary JavaScript in an administrator’s browser by registering a user…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"phpmyfaq","product":"phpmyfaq","affected":["phpmyfaq >= 4.0.14, < 4.0.16","phpmyfaq = 4.1.0"],"patched":["phpmyfaq 4.0.16"],"published":"2025-12-29","updated":"2026-10-05","sourceUpdated":"2026-10-05T19:10:00.210","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-68951","references":[{"url":"https://github.com/thorsten/phpMyFAQ/commit/61829e83411f7b28bc6fd1052bfde54c32c6c370","label":"security-advisories@github.com"},{"url":"https://github.com/thorsten/phpMyFAQ/commit/8211d1d25951b4c272443cfc3ef9c09b1363fd87","label":"security-advisories@github.com"},{"url":"https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-jv8r-hv7q-p6vc","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.0028,"epssPercentile":0.18633,"ingestedAt":"2026-10-05T19:30:59.955Z","slug":"CVE-2025-68951","body":"## Overview\n\nphpMyFAQ is an open source FAQ web application. Versions 4.0.14 and 4.0.15 have a stored cross-site scripting (XSS) vulnerability that allows an attacker to execute arbitrary JavaScript in an administrator’s browser by registering a user whose display name contains HTML entities. When an administrator views the admin user list, the payload is decoded server-side and rendered without escaping, resulting in script execution in the admin context. Version 4.0.16 contains a patch for the issue.\n\n## Affected\n\n- `phpmyfaq >= 4.0.14, < 4.0.16`\n- `phpmyfaq = 4.1.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `phpmyfaq 4.0.16`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}