VulnSea

thorsten has 11 CVEs on record. Disclosure cadence is accelerating: 9 in the last 90 days against 2 in the 90 before. The busiest recent month was September 2026 with 5. The median CVSS is 5.4 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-200 (3). Most affected products: thorsten/phpmyfaq (6), phpMyFAQ (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.4
Publish → KEV
Last 90 days
9 prev 2

Products

  • thorsten/phpmyfaq 6
  • phpMyFAQ 5
11
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

thorsten vulnerabilities

CVEs affecting thorsten, newest first. Open any entry for full detail, references, and exploit status.

11 CVEsRSS

CVE-2026-85593Medium· 5.4
2w ago

phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting vulnerability in FaqHelper::convertOldInternalLinks() that calls html_entity_decode() on sanitized FAQ content, reversing entity-encoding protection

phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting vulnerability in FaqHelper::convertOldInternalLinks() that calls html_entity_decode() on sanitized FAQ content, reversing entity-encoding protection. Authenticated user…

Sunlitthorsten · phpMyFAQEPSS 0.14%via NVD
CVE-2026-85591High· 7.1
2w ago

phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows authenticated attackers to change account passwords without verifying the current password

phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows authenticated attackers to change account passwords without verifying the current password. Attackers with s…

Twilightthorsten · phpMyFAQEPSS 0.30%via NVD
CVE-2026-85588Medium· 5.3
2w ago

phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files

phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attackers obtaining exported archives can extract the TOTP seed and generate valid one-time codes to bypass two-factor authen…

Sunlitthorsten · phpMyFAQEPSS 0.38%via NVD
CVE-2026-85586Medium· 6.9
2w ago

phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests

phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA protection and submit unlimited questions directly, causing da…

Sunlitthorsten · phpMyFAQEPSS 0.36%via NVD
CVE-2026-85589Medium· 5.3PoC
2w ago

phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerability in the admin dashboard API endpoints searches and content-health that enforce only authentication without permission checks

phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerability in the admin dashboard API endpoints searches and content-health that enforce only authentication without permission checks. Any authenticated user can access t…

Twilightthorsten · phpMyFAQEPSS 0.28%via NVD
GHSA-88g4-74f3-63x9Medium· 4.9
3w ago

phpMyFAQ has Potential Authenticated Path Traversal in PDF Export

phpMyFAQ has Potential Authenticated Path Traversal in PDF Export

Sunlitthorsten · thorsten/phpmyfaqvia GHSA
GHSA-mf8r-wm2w-f8c5Medium· 5.3
3w ago

phpMyFAQ public FAQ APIs expose inactive FAQ content

phpMyFAQ public FAQ APIs expose inactive FAQ content

Sunlitthorsten · thorsten/phpmyfaqvia GHSA
CVE-2026-47132Medium· 5.4
1mo ago

phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration

phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration

Sunlitthorsten · thorsten/phpmyfaqvia GHSA
GHSA-985r-q3qp-299hHigh· 8.1
2mo ago

phpMyFAQ has an incomplete fix for GHSA-xvp4-phqj-cjr3 — editUser() and updateUserRights() lack authorization guards

phpMyFAQ has an incomplete fix for GHSA-xvp4-phqj-cjr3 — editUser() and updateUserRights() lack authorization guards

Twilightthorsten · thorsten/phpmyfaqvia GHSA
CVE-2026-48488Low
3mo ago

phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing

phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing

Sunlitthorsten · thorsten/phpmyfaqEPSS 0.18%via GHSA
CVE-2026-49205Medium· 6.5
3mo ago

phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)

phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)

Sunlitthorsten · thorsten/phpmyfaqEPSS 0.39%via GHSA
thorsten vulnerabilities (CVEs) · VulnSea