Low severityNVD Advisory· Published Jun 8, 2026· Updated Jun 9, 2026
CVE-2026-48488
CVE-2026-48488
Description
phpMyFAQ is an open source FAQ web application. Prior to version 4.1.4, attachment passwords are hashed using SHA-1, a cryptographically broken algorithm. SHA-1 has been vulnerable to collision attacks since 2017 (SHAttered). Version 4.1.4 fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
thorsten/phpmyfaqPackagist | < 4.1.4 | 4.1.4 |
phpmyfaq/phpmyfaqPackagist | < 4.1.4 | 4.1.4 |
Affected products
1- Range: <4.1.4
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.