CVE-2025-68951Medium· 5.4▾ SunlitphpMyFAQ is an open source FAQ web application. Versions 4.0.14 and 4.0.15 have a stored cross-site scripting (XSS) vulnerability that allows an attacker to execute arbitrary JavaScript in an administrator’s browser by registering a user…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
phpMyFAQ is an open source FAQ web application. Versions 4.0.14 and 4.0.15 have a stored cross-site scripting (XSS) vulnerability that allows an attacker to execute arbitrary JavaScript in an administrator’s browser by registering a user whose display name contains HTML entities. When an administrator views the admin user list, the payload is decoded server-side and rendered without escaping, resulting in script execution in the admin context. Version 4.0.16 contains a patch for the issue.
phpmyfaq >= 4.0.14, < 4.0.16phpmyfaq = 4.1.0Upgrade past the affected range:
phpmyfaq 4.0.16Connected by shared product, vendor, weakness, or advisory.
CVE-2026-56736High· 8.2phpMyFAQ is an open source FAQ web application
CVE-2026-85593Medium· 5.4phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting vulnerability in FaqHelper::convertOldInternalLinks() that calls html_entity_decode() on sanitized FAQ content, reversing entity-encoding protection
CVE-2025-69200High· 7.5phpMyFAQ is an open source FAQ web application
CVE-2025-62519High· 7.2phpMyFAQ is an open source FAQ web application
CVE-2026-76208High· 8.2phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass vulnerability in AuthLdap::create()
CVE-2026-56738High· 8.5phpMyFAQ is an open source FAQ web application