Skip to main content

Vendor archive

phpmyfaq CVEs

Beta · best-effort

141 CVEs tagged to vendor phpmyfaq8 Critical, 38 High, 93 Medium, 2 Low, 0 Unrated.

CVE-2024-24574

Published Feb 5, 2024

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Unsafe echo of filename in phpMyFAQ\phpmyfaq\admin\attachments.php leads to…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22208

Published Feb 5, 2024

phpMyFAQ is an Open Source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The 'sharing FAQ' functionality allows any unauthenticated actor to misuse t…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22202

Published Feb 5, 2024

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. phpMyFAQ's user removal page allows an attacker to spoof another user's deta…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6890

Published Dec 16, 2023

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.17.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6889

Published Dec 16, 2023

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.17.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5867

Published Oct 31, 2023

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.2.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5866

Published Oct 31, 2023

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.2.1.

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5865

Published Oct 31, 2023

Insufficient Session Expiration in GitHub repository thorsten/phpmyfaq prior to 3.2.2.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-5864

Published Oct 31, 2023

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.1.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5863

Published Oct 31, 2023

Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.2.2.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5320

Published Sep 30, 2023

Cross-site Scripting (XSS) - DOM in GitHub repository thorsten/phpmyfaq prior to 3.1.18.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5319

Published Sep 30, 2023

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.18.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5317

Published Sep 30, 2023

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.18.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5316

Published Sep 30, 2023

Cross-site Scripting (XSS) - DOM in GitHub repository thorsten/phpmyfaq prior to 3.1.18.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5227

Published Sep 30, 2023

Unrestricted Upload of File with Dangerous Type in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-4007

Published Jul 31, 2023

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.16.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4006

Published Jul 31, 2023

Improper Neutralization of Formula Elements in a CSV File in GitHub repository thorsten/phpmyfaq prior to 3.1.16.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-3469

Published Jun 30, 2023

Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.2.0-beta.2.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2999

Published May 31, 2023

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2998

Published May 31, 2023

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2753

Published May 17, 2023

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.0-beta.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2752

Published May 17, 2023

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.0-beta.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2550

Published May 5, 2023

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.13.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2427

Published May 5, 2023

Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.13.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2429

Published Apr 30, 2023

Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.13.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 26-50 of 141 CVEsPage 2 of 6