VYPR

Phpmyfaq

by PhpMyAdmin

Source repositories

CVEs (192)

  • CVE-2024-28105HigMar 25, 2024
    risk 0.40cvss 7.2epss 0.01

    phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The category image upload function in phpmyfaq is vulnerable to manipulation of the `Content-type` and `lang` parameters, allowing attackers to upload malicious files with a…

  • CVE-2018-15899MedAug 27, 2018
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in MiniCMS 1.10. There is a post.php?date= XSS vulnerability.

  • CVE-2017-15809MedOct 23, 2017
    risk 0.40cvss 6.1epss 0.01

    In phpMyFaq before 2.9.9, there is XSS in admin/tags.main.php via a crafted tag.

  • CVE-2017-7579MedApr 7, 2017
    risk 0.40cvss 6.1epss 0.01

    inc/PMF/Faq.php in phpMyFAQ before 2.9.7 has XSS in the question field.

  • CVE-2026-85591HigSep 4, 2026
    risk 0.39cvss —epss 0.00

    phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows authenticated attackers to change account passwords without verifying the current password. Attackers with session access can submit a PUT request to…

  • CVE-2026-85590HigSep 4, 2026
    risk 0.39cvss —epss 0.00

    phpMyFAQ before 4.1.8 contains an authentication bypass vulnerability in its two-factor authentication (TOTP) disable functionality. The removeTwofactorConfig() handler (reachable via POST /api/user/remove-twofactor) verifies only that the user is logged in and that a valid CSRF…

  • CVE-2023-0793HigFeb 12, 2023
    risk 0.39cvss 7.1epss 0.01

    Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

  • CVE-2026-85586MedSep 4, 2026
    risk 0.38cvss —epss 0.00

    phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA protection and submit unlimited questions directly, causing database pollution and triggering outgoing…

  • CVE-2026-46361MedMay 15, 2026
    risk 0.38cvss 6.9epss 0.00

    phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in search.twig where result.question and result.answerPreview are rendered with the raw filter, disabling autoescape protection. Attackers with FAQ editor privileges can inject HTML-entity-encoded…

  • CVE-2017-15727MedOct 22, 2017
    risk 0.38cvss 5.4epss 0.02

    In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment.

  • CVE-2022-4407MedDec 11, 2022
    risk 0.36cvss 6.1epss 0.05

    Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.9.

  • CVE-2022-3766MedOct 31, 2022
    risk 0.36cvss 6.1epss 0.06

    Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

  • CVE-2026-76210MedAug 19, 2026
    risk 0.35cvss 6.5epss 0.00

    phpMyFAQ before 4.1.6 does not adequately sanitize HTML in FAQ answers before generating PDFs via TCPDF. An attacker with permission to create or edit FAQ content can embed an tag whose src references a local file under the web root's content/ directory (e.g.,…

  • CVE-2026-49205MedJun 18, 2026
    risk 0.35cvss 6.5epss 0.00

    phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryController. CVE-2026-24421 addressed this in the BackupController by adding: $this->userHasPermission(PermissionType::BACKUP). The same fix was not applied to 4…

  • CVE-2026-46362MedMay 15, 2026
    risk 0.35cvss 6.5epss 0.00

    phpMyFAQ before 4.1.2 contains an authorization bypass vulnerability in AbstractAdministrationController::userHasPermission() that fails to terminate execution after sending a forbidden response. Attackers can access all permission-protected admin pages by requesting their URLs…

  • CVE-2026-45008MedMay 15, 2026
    risk 0.35cvss 6.5epss 0.00

    phpMyFAQ before 4.1.2 contains a path traversal vulnerability in Client::deleteClientFolder that allows admins with INSTANCE_DELETE permission to delete arbitrary directories. Attackers can submit traversal sequences like https://../../../ in the client URL parameter to…

  • CVE-2024-24574MedFeb 5, 2024
    risk 0.35cvss 6.5epss 0.01

    phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Unsafe echo of filename in phpMyFAQ\phpmyfaq\admin\attachments.php leads to allowed execution of JavaScript code in client side (XSS). This vulnerability has been patched in…

  • CVE-2024-22208MedFeb 5, 2024
    risk 0.35cvss 6.5epss 0.01

    phpMyFAQ is an Open Source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The 'sharing FAQ' functionality allows any unauthenticated actor to misuse the phpMyFAQ application to send arbitrary emails to a large range of targets. The phpMyFAQ…

  • CVE-2023-0792MedFeb 12, 2023
    risk 0.35cvss 6.5epss 0.01

    Code Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

  • CVE-2004-2257MedDec 31, 2004
    risk 0.35cvss 5.3epss 0.02

    phpMyFAQ 1.4.0 allows remote attackers to access the Image Manager to upload or delete images without authorization via a direct request.

Page 4 of 10