VYPR

Phpmyfaq

by PhpMyAdmin

Source repositories

CVEs (195)

  • CVE-2017-11187CriJul 12, 2017
    risk 0.64cvss 9.8epss 0.01

    phpMyFAQ before 2.9.8 does not properly mitigate brute-force attacks that try many passwords in attempted logins quickly.

  • CVE-2017-15808HigOct 23, 2017
    risk 0.60cvss 8.8epss 0.01

    In phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config.php.

  • CVE-2017-15730HigOct 22, 2017
    risk 0.60cvss 8.8epss 0.02

    In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php.

  • CVE-2026-75918HigAug 19, 2026
    risk 0.57cvss 8.8epss 0.00

    phpMyFAQ before 4.1.7 stores password reset tokens in a publicly accessible tracking file when user tracking is enabled. Unauthenticated attackers can read the tracking file at content/core/data/trackingDDMMYYYY to extract reset tokens and replay them against the password reset…

  • CVE-2026-56396HigJun 21, 2026
    risk 0.57cvss 8.8epss 0.00

    phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin users with edit_user permission can set is_superadmin flag or grant arbitrary rights…

  • CVE-2026-46364CriMay 15, 2026
    risk 0.57cvss 9.8epss 0.02

    phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector() and BuiltinCaptcha::saveCaptcha() methods that interpolate unsanitized User-Agent headers into DELETE and INSERT queries. Unauthenticated attackers can exploit the…

  • CVE-2023-53929HigDec 17, 2025
    risk 0.57cvss 8.8epss 0.01

    phpMyFAQ 3.1.12 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into their profile names. Attackers can modify their user profile name with a payload like 'calc|a!z|' to trigger code execution when an administrator exports user…

  • CVE-2023-5865CriOct 31, 2023
    risk 0.57cvss 9.8epss 0.01

    Insufficient Session Expiration in GitHub repository thorsten/phpmyfaq prior to 3.2.2.

  • CVE-2023-5227CriSep 30, 2023
    risk 0.57cvss 9.8epss 0.01

    Unrestricted Upload of File with Dangerous Type in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

  • CVE-2023-4006CriJul 31, 2023
    risk 0.57cvss 9.8epss 0.01

    Improper Neutralization of Formula Elements in a CSV File in GitHub repository thorsten/phpmyfaq prior to 3.1.16.

  • CVE-2023-2429CriApr 30, 2023
    risk 0.57cvss 9.8epss 0.01

    Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.13.

  • CVE-2023-0311CriJan 15, 2023
    risk 0.57cvss 9.8epss 0.01

    Improper Authentication in GitHub repository thorsten/phpmyfaq prior to 3.1.10.

  • CVE-2023-0307CriJan 15, 2023
    risk 0.57cvss 9.8epss 0.01

    Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.10.

  • CVE-2022-3754CriOct 29, 2022
    risk 0.57cvss 9.8epss 0.01

    Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

  • CVE-2018-16650HigSep 7, 2018
    risk 0.57cvss 8.8epss 0.01

    phpMyFAQ before 2.9.11 allows CSRF.

  • CVE-2017-15733HigOct 22, 2017
    risk 0.57cvss 8.8epss 0.01

    In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/ajax.attachment.php and admin/att.main.php.

  • CVE-2017-15732HigOct 22, 2017
    risk 0.57cvss 8.8epss 0.01

    In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/news.php.

  • CVE-2017-15731HigOct 22, 2017
    risk 0.57cvss 8.8epss 0.01

    In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.adminlog.php.

  • CVE-2017-15729HigOct 22, 2017
    risk 0.57cvss 8.8epss 0.01

    In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for adding a glossary.

  • CVE-2026-76208HigAug 19, 2026
    risk 0.53cvss 8.2epss 0.00

    phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass vulnerability in AuthLdap::create(). When LDAP authentication is enabled, after a successful LDAP bind the code calls User::setStatus('active') unconditionally, which overwrites the account_status column of a…

Page 1 of 10