phpmyfaq/phpmyfaq vulnerabilities
CVEs whose affected-version data names the phpmyfaq/phpmyfaq package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
6 CVEsRSS
GHSA-88g4-74f3-63x9Medium· 4.9phpMyFAQ has Potential Authenticated Path Traversal in PDF Export
phpMyFAQ has Potential Authenticated Path Traversal in PDF Export
▾ Sunlitthorsten · thorsten/phpmyfaqvia GHSA
GHSA-mf8r-wm2w-f8c5Medium· 5.3phpMyFAQ public FAQ APIs expose inactive FAQ content
phpMyFAQ public FAQ APIs expose inactive FAQ content
▾ Sunlitthorsten · thorsten/phpmyfaqvia GHSA
GHSA-pg62-f8g4-4wqhHigh· 8.8phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold
phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold
▾ Twilightphpmyfaq · phpmyfaq/phpmyfaqvia GHSA
GHSA-985r-q3qp-299hHigh· 8.1phpMyFAQ has an incomplete fix for GHSA-xvp4-phqj-cjr3 — editUser() and updateUserRights() lack authorization guards
phpMyFAQ has an incomplete fix for GHSA-xvp4-phqj-cjr3 — editUser() and updateUserRights() lack authorization guards
▾ Twilightthorsten · thorsten/phpmyfaqvia GHSA
CVE-2026-48488LowphpMyFAQ has Weak Cryptography - SHA1 for Password Hashing
phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing
▾ Sunlitthorsten · thorsten/phpmyfaqEPSS 0.18%via GHSA
CVE-2026-49205Medium· 6.5phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)
phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)
▾ Sunlitthorsten · thorsten/phpmyfaqEPSS 0.39%via GHSA