thorsten has 11 CVEs on record. Disclosure cadence is accelerating: 9 in the last 90 days against 2 in the 90 before. The busiest recent month was September 2026 with 5. The median CVSS is 5.4 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-200 (3). Most affected products: thorsten/phpmyfaq (6), phpMyFAQ (5).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.4
- Publish → KEV
- —
- Last 90 days
- 9 prev 2
Worst active — by depth score
GHSA-985r-q3qp-299hHigh· 8.1phpMyFAQ has an incomplete fix for GHSA-xvp4-phqj-cjr3 — editUser() and updateUserRights() lack authorization guards45CVE-2026-85589Medium· 5.3phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerability in the admin dashboard API endpoints searches and content-health that enforce only authentication without permission checks41CVE-2026-85591High· 7.1phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows authenticated attackers to change account passwords without verifying the current password39CVE-2026-85586Medium· 6.9phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests38CVE-2026-49205Medium· 6.5phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)36
thorsten vulnerabilities
CVEs affecting thorsten, newest first. Open any entry for full detail, references, and exploit status.
11 CVEsRSS
CVE-2026-85593Medium· 5.4phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting vulnerability in FaqHelper::convertOldInternalLinks() that calls html_entity_decode() on sanitized FAQ content, reversing entity-encoding protection
phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting vulnerability in FaqHelper::convertOldInternalLinks() that calls html_entity_decode() on sanitized FAQ content, reversing entity-encoding protection. Authenticated user…
CVE-2026-85591High· 7.1phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows authenticated attackers to change account passwords without verifying the current password
phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows authenticated attackers to change account passwords without verifying the current password. Attackers with s…
CVE-2026-85588Medium· 5.3phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files
phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attackers obtaining exported archives can extract the TOTP seed and generate valid one-time codes to bypass two-factor authen…
CVE-2026-85586Medium· 6.9phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests
phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA protection and submit unlimited questions directly, causing da…
CVE-2026-85589Medium· 5.3PoCphpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerability in the admin dashboard API endpoints searches and content-health that enforce only authentication without permission checks
phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerability in the admin dashboard API endpoints searches and content-health that enforce only authentication without permission checks. Any authenticated user can access t…
GHSA-88g4-74f3-63x9Medium· 4.9phpMyFAQ has Potential Authenticated Path Traversal in PDF Export
phpMyFAQ has Potential Authenticated Path Traversal in PDF Export
GHSA-mf8r-wm2w-f8c5Medium· 5.3phpMyFAQ public FAQ APIs expose inactive FAQ content
phpMyFAQ public FAQ APIs expose inactive FAQ content
CVE-2026-47132Medium· 5.4phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration
phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration
GHSA-985r-q3qp-299hHigh· 8.1phpMyFAQ has an incomplete fix for GHSA-xvp4-phqj-cjr3 — editUser() and updateUserRights() lack authorization guards
phpMyFAQ has an incomplete fix for GHSA-xvp4-phqj-cjr3 — editUser() and updateUserRights() lack authorization guards
CVE-2026-48488LowphpMyFAQ has Weak Cryptography - SHA1 for Password Hashing
phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing
CVE-2026-49205Medium· 6.5phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)
phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)