thorsten phpMyFAQ
12 known vulnerabilities in thorsten phpMyFAQ, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-56738 CVSS 8.5 high phpMyFAQ is an open source FAQ web application. The `StopWords::add()` method inversions prior to 4.1.6 builds a SQL `INSERT` statement…
- CVE-2026-47132 CVSS 5.4 medium phpMyFAQ is an open source FAQ web application. Prior to version 4.2.0-alpha, an authenticated SQL LIKE wildcard injection vulnerability…
- CVE-2026-56737 CVSS 8.1 high phpMyFAQ is an open source FAQ web application. Versions 3.2.0 through 4.1.5 contain an authentication bypass in its public two-factor…
- CVE-2026-56736 CVSS 8.2 high phpMyFAQ is an open source FAQ web application. A stored cross-site scripting (XSS) vulnerability in versions prior to 4.2.0-alpha allows…
- CVE-2026-85593 CVSS 5.1 medium phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting vulnerability in FaqHelper::convertOldInternalLinks() that calls…
- CVE-2026-85592 CVSS 6.3 medium phpMyFAQ before 4.1.8 contains an authorization bypass vulnerability in the question creation endpoint where the…
- CVE-2026-85591 CVSS 7.1 high phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows…
- CVE-2026-85590 CVSS 7.1 high phpMyFAQ before 4.1.8 contains an authentication bypass vulnerability in its two-factor authentication (TOTP) disable functionality. The…
- CVE-2026-85589 CVSS 5.3 medium phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerability in the admin dashboard API endpoints searches and…
- CVE-2026-85588 CVSS 5.3 medium phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attackers obtaining…
- CVE-2026-85587 CVSS 5.3 medium phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and…
- CVE-2026-85586 CVSS 6.9 medium phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests…