---
id: CVE-2025-68951
title: phpMyFAQ is an open source FAQ web application
summary: >-
  phpMyFAQ is an open source FAQ web application. Versions 4.0.14 and 4.0.15
  have a stored cross-site scripting (XSS) vulnerability that allows an attacker
  to execute arbitrary JavaScript in an administrator’s browser by registering a
  user…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: phpmyfaq
product: phpmyfaq
affected:
  - 'phpmyfaq >= 4.0.14, < 4.0.16'
  - phpmyfaq = 4.1.0
patched:
  - phpmyfaq 4.0.16
published: '2025-12-29'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T19:10:00.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-68951'
references:
  - url: >-
      https://github.com/thorsten/phpMyFAQ/commit/61829e83411f7b28bc6fd1052bfde54c32c6c370
    label: security-advisories@github.com
  - url: >-
      https://github.com/thorsten/phpMyFAQ/commit/8211d1d25951b4c272443cfc3ef9c09b1363fd87
    label: security-advisories@github.com
  - url: >-
      https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-jv8r-hv7q-p6vc
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.0028
epssPercentile: 0.18633
ingestedAt: '2026-10-05T19:30:59.955Z'
---

## Overview

phpMyFAQ is an open source FAQ web application. Versions 4.0.14 and 4.0.15 have a stored cross-site scripting (XSS) vulnerability that allows an attacker to execute arbitrary JavaScript in an administrator’s browser by registering a user whose display name contains HTML entities. When an administrator views the admin user list, the payload is decoded server-side and rendered without escaping, resulting in script execution in the admin context. Version 4.0.16 contains a patch for the issue.

## Affected

- `phpmyfaq >= 4.0.14, < 4.0.16`
- `phpmyfaq = 4.1.0`

## Remediation

Upgrade past the affected range:

- `phpmyfaq 4.0.16`
