---
id: CVE-2026-85586
title: >-
  phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store
  parameter is set to 'now' in question submission requests
summary: >-
  phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store
  parameter is set to 'now' in question submission requests. Unauthenticated
  attackers can bypass CAPTCHA protection and submit unlimited questions
  directly, causing da…
severity: medium
cvss: 6.9
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-799
vendor: thorsten
product: phpMyFAQ
affected:
  - phpMyFAQ < 4.1.8
published: '2026-09-04'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T16:17:59.233'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85586'
references:
  - url: >-
      https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-72vj-pvm4-mm7x
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/phpmyfaq-before-4.1.8-captcha-bypass-via-store-parameter
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-10T14:28:22.626469Z'
cvssSource: cna
epss: 0.00359
epssPercentile: 0.29728
ingestedAt: '2026-09-08T20:10:03.164Z'
---

## Overview

phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA protection and submit unlimited questions directly, causing database pollution and triggering outgoing mail notifications.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
