VulnSea

phpmyfaq/phpmyfaq vulnerabilities

CVEs whose affected-version data names the phpmyfaq/phpmyfaq package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

GHSA-88g4-74f3-63x9Medium· 4.9
4w ago

phpMyFAQ has Potential Authenticated Path Traversal in PDF Export

phpMyFAQ has Potential Authenticated Path Traversal in PDF Export

Sunlitthorsten · thorsten/phpmyfaqvia GHSA
GHSA-mf8r-wm2w-f8c5Medium· 5.3
4w ago

phpMyFAQ public FAQ APIs expose inactive FAQ content

phpMyFAQ public FAQ APIs expose inactive FAQ content

Sunlitthorsten · thorsten/phpmyfaqvia GHSA
GHSA-pg62-f8g4-4wqhHigh· 8.8
4w ago

phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold

phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold

Twilightphpmyfaq · phpmyfaq/phpmyfaqvia GHSA
GHSA-985r-q3qp-299hHigh· 8.1
2mo ago

phpMyFAQ has an incomplete fix for GHSA-xvp4-phqj-cjr3 — editUser() and updateUserRights() lack authorization guards

phpMyFAQ has an incomplete fix for GHSA-xvp4-phqj-cjr3 — editUser() and updateUserRights() lack authorization guards

Twilightthorsten · thorsten/phpmyfaqvia GHSA
CVE-2026-48488Low
3mo ago

phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing

phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing

Sunlitthorsten · thorsten/phpmyfaqEPSS 0.18%via GHSA
CVE-2026-49205Medium· 6.5
3mo ago

phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)

phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)

Sunlitthorsten · thorsten/phpmyfaqEPSS 0.39%via GHSA
phpmyfaq/phpmyfaq vulnerabilities (CVEs) · VulnSea