---
id: CVE-2025-69200
title: phpMyFAQ is an open source FAQ web application
summary: >-
  phpMyFAQ is an open source FAQ web application. In versions prior to 4.0.16,
  an unauthenticated remote attacker can trigger generation of a configuration
  backup ZIP via `POST /api/setup/backup` and then download the generated ZIP
  from a …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-202
vendor: phpmyfaq
product: phpmyfaq
affected:
  - phpmyfaq < 4.0.16
  - phpmyfaq = 4.1.0
patched:
  - phpmyfaq 4.0.16
published: '2025-12-29'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T19:10:00.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-69200'
references:
  - url: >-
      https://github.com/thorsten/phpMyFAQ/commit/b0e99ee3695152115841cb546d8dce64ceb8c29a
    label: security-advisories@github.com
  - url: >-
      https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-9cg9-4h4f-j6fg
    label: security-advisories@github.com
tags:
  - nvd
  - exploit-available
epss: 0.02141
epssPercentile: 0.81412
exploits:
  nuclei:
    - CVE-2025-69200
  checkedAt: '2026-10-05T19:31:35.330Z'
exploitAvailable: true
ingestedAt: '2026-10-05T19:30:59.956Z'
---

## Overview

phpMyFAQ is an open source FAQ web application. In versions prior to 4.0.16, an unauthenticated remote attacker can trigger generation of a configuration backup ZIP via `POST /api/setup/backup` and then download the generated ZIP from a web-accessible location. The ZIP contains sensitive configuration files (e.g., `database.php` with database credentials), leading to high-impact information disclosure and potential follow-on compromise. Version 4.0.16 fixes the issue.

## Affected

- `phpmyfaq < 4.0.16`
- `phpmyfaq = 4.1.0`

## Remediation

Upgrade past the affected range:

- `phpmyfaq 4.0.16`
