Skip to main content

Vendor archive

phpmyfaq CVEs

Beta · best-effort

141 CVEs tagged to vendor phpmyfaq8 Critical, 38 High, 93 Medium, 2 Low, 0 Unrated.

CVE-2014-6049

Published Aug 28, 2018

phpMyFAQ before 2.8.13 allows remote authenticated users with admin privileges to bypass authorization via a crafted instance ID parameter.

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-6048

Published Aug 28, 2018

phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6047

Published Aug 28, 2018

phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by leveraging incorrect "download an attachment" permission checks.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6046

Published Aug 28, 2018

Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyFAQ before 2.8.13 allow remote attackers to hijack the authentication of unspecified users for requests that (1)…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-6045

Published Aug 28, 2018

SQL injection vulnerability in phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to execute arbitrary SQL commands via vectors involving the restor…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15809

Published Oct 23, 2017

In phpMyFaq before 2.9.9, there is XSS in admin/tags.main.php via a crafted tag.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15735

Published Oct 22, 2017

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15734

Published Oct 22, 2017

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15733

Published Oct 22, 2017

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/ajax.attachment.php and admin/att.main.php.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15732

Published Oct 22, 2017

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/news.php.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15731

Published Oct 22, 2017

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.adminlog.php.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15730

Published Oct 22, 2017

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15729

Published Oct 22, 2017

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for adding a glossary.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15728

Published Oct 22, 2017

In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via metaDescription or metaKeywords.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15727

Published Oct 22, 2017

In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14619

Published Sep 20, 2017

Cross-site scripting (XSS) vulnerability in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the "Title of your FAQ" field in the Configur…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14618

Published Sep 20, 2017

Cross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the Questions field in an…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11187

Published Jul 12, 2017

phpMyFAQ before 2.9.8 does not properly mitigate brute-force attacks that try many passwords in attempted logins quickly.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-0814

Published Feb 14, 2014

Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.8.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0813

Published Feb 14, 2014

Cross-site request forgery (CSRF) vulnerability in phpMyFAQ before 2.8.6 allows remote attackers to hijack the authentication of arbitrary users for requests that modify settings.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4821

Published Oct 22, 2012

Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.6.9 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3783

Published Sep 24, 2011

phpMyFAQ 2.6.13 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrat…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 101-125 of 141 CVEsPage 5 of 6