Skip to main content

Vendor archive

phpmyfaq CVEs

Beta · best-effort

141 CVEs tagged to vendor phpmyfaq8 Critical, 38 High, 93 Medium, 2 Low, 0 Unrated.

CVE-2026-34974

Published Apr 2, 2026

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the regex-based SVG sanitizer in phpMyFAQ (SvgSanitizer.php) can be bypassed using HTML entity encoding in…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-34973

Published Apr 2, 2026

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the searchCustomPages() method in phpmyfaq/src/phpMyFAQ/Search.php uses real_escape_string() (via escape())…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-34729

Published Apr 2, 2026

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, there is a stored XSS vulnerability via Regex Bypass in Filter::removeAttributes(). This issue has been pat…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-34728

Published Apr 2, 2026

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the MediaBrowserController::index() method handles file deletion for the media browser. When the fileRemove…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-32629

Published Apr 2, 2026

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, an unauthenticated attacker can submit a guest FAQ with an email address that is syntactically valid per RF…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-27836

Published Feb 27, 2026

phpMyFAQ is an open source FAQ web application. Prior to version 4.0.18, the WebAuthn prepare endpoint (`/api/webauthn/prepare`) creates new active user accounts without any authe…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-24422

Published Jan 24, 2026

phpMyFAQ is an open source FAQ web application. In versions 4.0.16 and below, multiple public API endpoints improperly expose sensitive user information due to insufficient access…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24420

Published Jan 24, 2026

phpMyFAQ is an open source FAQ web application. Versions 4.0.16 and below allow an authenticated user without the dlattachment permission to download FAQ attachments due to a inco…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24421

Published Jan 24, 2026

phpMyFAQ is an open source FAQ web application. Versions 4.0.16 and below have flawed authorization logic which exposes the /api/setup/backup endpoint to any authenticated user de…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-69200

Published Dec 29, 2025

phpMyFAQ is an open source FAQ web application. In versions prior to 4.0.16, an unauthenticated remote attacker can trigger generation of a configuration backup ZIP via `POST /api…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-68951

Published Dec 29, 2025

phpMyFAQ is an open source FAQ web application. Versions 4.0.14 and 4.0.15 have a stored cross-site scripting (XSS) vulnerability that allows an attacker to execute arbitrary Java…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-53929

Published Dec 17, 2025

phpMyFAQ 3.1.12 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into their profile names. Attackers can modify their user profi…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62519

Published Nov 17, 2025

phpMyFAQ is an open source FAQ web application. Prior to version 4.0.14, an authenticated SQL injection vulnerability in the main configuration update functionality of phpMyFAQ al…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59943

Published Oct 3, 2025

phpMyFAQ is an open source FAQ web application. Versions 4.0-nightly-2025-10-03 and below do not enforce uniqueness of email addresses during user registration. This allows multip…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-56199

Published Jan 2, 2025

phpMyFAQ is an open source FAQ web application. Starting no later than version 3.2.10 and prior to version 4.0.2, an attacker can inject malicious HTML content into the FAQ editor…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-55889

Published Dec 13, 2024

phpMyFAQ is an open source FAQ web application. Prior to version 3.2.10, a vulnerability exists in the FAQ Record component where a privileged attacker can trigger a file download…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-54141

Published Dec 6, 2024

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Prior to 4.0.0, phpMyFAQ exposes the database (ie postgreSQL) server's crede…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-29196

Published Mar 26, 2024

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. There is a Path Traversal vulnerability in Attachments that allows attackers…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-29179

Published Mar 25, 2024

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. An attacker with admin privileges can upload an attachment containing JS cod…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28108

Published Mar 25, 2024

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Due to insufficient validation on the `contentLink` parameter, it is possibl…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28107

Published Mar 25, 2024

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. A SQL injection vulnerability has been discovered in the `insertentry` & `s…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28106

Published Mar 25, 2024

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. By manipulating the news parameter in a POST request, an attacker can inject…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28105

Published Mar 25, 2024

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The category image upload function in phpmyfaq is vulnerable to manipulation…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27300

Published Mar 25, 2024

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The `email` field in phpMyFAQ's user control panel page is vulnerable to sto…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-27299

Published Mar 25, 2024

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. A SQL injection vulnerability has been discovered in the the "Add News" func…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 141 CVEsPage 1 of 6