VYPR

Phpmyfaq

by PhpMyAdmin

Source repositories

CVEs (56)

  • CVE-2017-11187CriJul 12, 2017
    risk 0.64cvss 9.8epss 0.01

    phpMyFAQ before 2.9.8 does not properly mitigate brute-force attacks that try many passwords in attempted logins quickly.

  • CVE-2017-15808HigOct 23, 2017
    risk 0.60cvss 8.8epss 0.01

    In phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config.php.

  • CVE-2017-15730HigOct 22, 2017
    risk 0.60cvss 8.8epss 0.02

    In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php.

  • CVE-2017-15733HigOct 22, 2017
    risk 0.57cvss 8.8epss 0.01

    In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/ajax.attachment.php and admin/att.main.php.

  • CVE-2017-15732HigOct 22, 2017
    risk 0.57cvss 8.8epss 0.01

    In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/news.php.

  • CVE-2017-15731HigOct 22, 2017
    risk 0.57cvss 8.8epss 0.01

    In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.adminlog.php.

  • CVE-2017-15729HigOct 22, 2017
    risk 0.57cvss 8.8epss 0.01

    In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for adding a glossary.

  • CVE-2014-6046HigAug 28, 2018
    risk 0.53cvss 8.8epss 0.02

    Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyFAQ before 2.8.13 allow remote attackers to hijack the authentication of unspecified users for requests that (1) delete active users by leveraging improper validation of CSRF tokens or that (2) delete open…

  • CVE-2017-15735HigOct 22, 2017
    risk 0.53cvss 8.8epss 0.01

    In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary.

  • CVE-2017-15734HigOct 22, 2017
    risk 0.53cvss 8.8epss 0.01

    In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php.

  • CVE-2026-35671HigMay 28, 2026
    risk 0.50cvss 8.8epss 0.00

    phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated administrators to change any user's password without authorization verification. An attacker with low-privilege admin credentials…

  • CVE-2026-34728HigApr 2, 2026
    risk 0.50cvss 8.7epss 0.01

    phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the MediaBrowserController::index() method handles file deletion for the media browser. When the fileRemove action is triggered, the user-supplied name parameter is concatenated with the base upload…

  • CVE-2018-16651HigSep 7, 2018
    risk 0.47cvss 7.2epss 0.01

    The admin backend in phpMyFAQ before 2.9.11 allows CSV injection in reports.

  • CVE-2026-35676HigMay 28, 2026
    risk 0.46cvss 8.2epss 0.00

    phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint that allows attackers to change account passwords without token validation. Attackers can enumerate valid username and email pairs and force immediate password…

  • CVE-2026-35675HigMay 28, 2026
    risk 0.46cvss 8.2epss 0.00

    phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthenticated attackers to reset any user account password without token verification or email confirmation. Attackers can enumerate valid usernames, obtain…

  • CVE-2014-6045HigAug 28, 2018
    risk 0.43cvss 7.2epss 0.02

    SQL injection vulnerability in phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to execute arbitrary SQL commands via vectors involving the restore function.

  • CVE-2017-14619MedSep 20, 2017
    risk 0.43cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the "Title of your FAQ" field in the Configuration Module.

  • CVE-2026-35672HigMay 28, 2026
    risk 0.42cvss 7.5epss 0.00

    phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in API v4.0 where the default empty api.apiClientToken allows unauthenticated users to create and modify FAQ entries. Attackers can send an empty x-pmf-token header to bypass token validation and inject…

  • CVE-2018-15899MedAug 27, 2018
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in MiniCMS 1.10. There is a post.php?date= XSS vulnerability.

  • CVE-2017-15809MedOct 23, 2017
    risk 0.40cvss 6.1epss 0.01

    In phpMyFaq before 2.9.9, there is XSS in admin/tags.main.php via a crafted tag.

Page 1 of 3