VulnSea

phpmyfaq vulnerabilities

CVEs whose affected-version data names the phpmyfaq package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

9 CVEsRSS

CVE-2026-56738High· 8.5
6d ago

phpMyFAQ is an open source FAQ web application

phpMyFAQ is an open source FAQ web application. The `StopWords::add()` method inversions prior to 4.1.6 builds a SQL `INSERT` statement using `sprintf()` and inserts the user-supplied stop word value directly into the query string withou…

▾ Twilightthorsten · phpMyFAQEPSS 0.26%via NVD
CVE-2026-56737High· 8.1PoC
6d ago

phpMyFAQ is an open source FAQ web application

phpMyFAQ is an open source FAQ web application. Versions 3.2.0 through 4.1.5 contain an authentication bypass in its public two-factor authentication verification flow: an unauthenticated attacker can submit an account’s numeric user ID …

▾ Midnightthorsten · phpMyFAQEPSS 0.40%via NVD
CVE-2026-56736High· 8.2PoC
6d ago

phpMyFAQ is an open source FAQ web application

phpMyFAQ is an open source FAQ web application. A stored cross-site scripting (XSS) vulnerability in versions prior to 4.2.0-alpha allows any unauthenticated user (or low-privileged registered user) to inject arbitrary JavaScript that ex…

▾ Midnightthorsten · phpMyFAQEPSS 0.24%via NVD
CVE-2026-85593Medium· 5.4
3w ago

phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting vulnerability in FaqHelper::convertOldInternalLinks() that calls html_entity_decode() on sanitized FAQ content, reversing entity-encoding protection

phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting vulnerability in FaqHelper::convertOldInternalLinks() that calls html_entity_decode() on sanitized FAQ content, reversing entity-encoding protection. Authenticated user…

▾ Sunlitthorsten · phpMyFAQEPSS 0.24%via NVD
CVE-2026-85591High· 7.1
3w ago

phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows authenticated attackers to change account passwords without verifying the current password

phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows authenticated attackers to change account passwords without verifying the current password. Attackers with s…

▾ Twilightthorsten · phpMyFAQEPSS 0.52%via NVD
CVE-2026-85588Medium· 5.3
3w ago

phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files

phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attackers obtaining exported archives can extract the TOTP seed and generate valid one-time codes to bypass two-factor authen…

▾ Sunlitthorsten · phpMyFAQEPSS 0.53%via NVD
CVE-2026-85586Medium· 6.9
3w ago

phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests

phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA protection and submit unlimited questions directly, causing da…

▾ Sunlitthorsten · phpMyFAQEPSS 0.49%via NVD
CVE-2026-85589Medium· 5.3PoC
3w ago

phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerability in the admin dashboard API endpoints searches and content-health that enforce only authentication without permission checks

phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerability in the admin dashboard API endpoints searches and content-health that enforce only authentication without permission checks. Any authenticated user can access t…

▾ Twilightthorsten · phpMyFAQEPSS 0.49%via NVD
CVE-2026-76208High· 8.2PoC
1mo ago

phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass vulnerability in AuthLdap::create()

phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass vulnerability in AuthLdap::create(). When LDAP authentication is enabled, after a successful LDAP bind the code calls User::setStatus('active') unconditionally, which…

▾ Midnightphpmyfaq · phpmyfaqEPSS 0.44%via NVD
phpmyfaq vulnerabilities (CVEs) · VulnSea