VYPR

Phpmyfaq

by Thorsten

Source repositories

CVEs (24)

  • CVE-2024-28108MedMar 25, 2024
    risk 0.24cvss 4.7epss 0.01

    phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Due to insufficient validation on the `contentLink` parameter, it is possible for unauthenticated users to inject HTML code to the page which might affect other users. _Also,…

  • CVE-2024-28106MedMar 25, 2024
    risk 0.21cvss 4.3epss 0.01

    phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. By manipulating the news parameter in a POST request, an attacker can inject malicious JavaScript code. Upon browsing to the compromised news page, the XSS payload triggers.…

  • CVE-2024-29196LowMar 26, 2024
    risk 0.18cvss 3.8epss 0.01

    phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. There is a Path Traversal vulnerability in Attachments that allows attackers with admin rights to upload malicious files to other locations of the web root. This vulnerability…

  • CVE-2026-57996HigJul 15, 2026
    risk 0.00cvss 8.8epss 0.00

    phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that allows non-SuperAdmin administrators to create SuperAdmin accounts. A delegated administrator with USER_ADD/EDIT/DELETE permissions can call POST /admin/api/user/add with…

Page 2 of 2