Phpmyfaq
by PhpMyAdmin
Source repositories
CVEs (192)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-28105 | Hig | 0.40 | 7.2 | 0.01 | Mar 25, 2024 | phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The category image upload function in phpmyfaq is vulnerable to manipulation of the `Content-type` and `lang` parameters, allowing attackers to upload malicious files with a… | ||
| CVE-2018-15899 | Med | 0.40 | 6.1 | 0.01 | Aug 27, 2018 | An issue was discovered in MiniCMS 1.10. There is a post.php?date= XSS vulnerability. | ||
| CVE-2017-15809 | Med | 0.40 | 6.1 | 0.01 | Oct 23, 2017 | In phpMyFaq before 2.9.9, there is XSS in admin/tags.main.php via a crafted tag. | ||
| CVE-2017-7579 | Med | 0.40 | 6.1 | 0.01 | Apr 7, 2017 | inc/PMF/Faq.php in phpMyFAQ before 2.9.7 has XSS in the question field. | ||
| CVE-2026-85591 | Hig | 0.39 | — | 0.00 | Sep 4, 2026 | phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows authenticated attackers to change account passwords without verifying the current password. Attackers with session access can submit a PUT request to… | ||
| CVE-2026-85590 | Hig | 0.39 | — | 0.00 | Sep 4, 2026 | phpMyFAQ before 4.1.8 contains an authentication bypass vulnerability in its two-factor authentication (TOTP) disable functionality. The removeTwofactorConfig() handler (reachable via POST /api/user/remove-twofactor) verifies only that the user is logged in and that a valid CSRF… | ||
| CVE-2023-0793 | Hig | 0.39 | 7.1 | 0.01 | Feb 12, 2023 | Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.11. | ||
| CVE-2026-85586 | Med | 0.38 | — | 0.00 | Sep 4, 2026 | phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA protection and submit unlimited questions directly, causing database pollution and triggering outgoing… | ||
| CVE-2026-46361 | Med | 0.38 | 6.9 | 0.00 | May 15, 2026 | phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in search.twig where result.question and result.answerPreview are rendered with the raw filter, disabling autoescape protection. Attackers with FAQ editor privileges can inject HTML-entity-encoded… | ||
| CVE-2017-15727 | Med | 0.38 | 5.4 | 0.02 | Oct 22, 2017 | In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment. | ||
| CVE-2022-4407 | Med | 0.36 | 6.1 | 0.05 | Dec 11, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.9. | ||
| CVE-2022-3766 | Med | 0.36 | 6.1 | 0.06 | Oct 31, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8. | ||
| CVE-2026-76210 | Med | 0.35 | 6.5 | 0.00 | Aug 19, 2026 | phpMyFAQ before 4.1.6 does not adequately sanitize HTML in FAQ answers before generating PDFs via TCPDF. An attacker with permission to create or edit FAQ content can embed an tag whose src references a local file under the web root's content/ directory (e.g.,… | ||
| CVE-2026-49205 | Med | 0.35 | 6.5 | 0.00 | Jun 18, 2026 | phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryController. CVE-2026-24421 addressed this in the BackupController by adding: $this->userHasPermission(PermissionType::BACKUP). The same fix was not applied to 4… | ||
| CVE-2026-46362 | Med | 0.35 | 6.5 | 0.00 | May 15, 2026 | phpMyFAQ before 4.1.2 contains an authorization bypass vulnerability in AbstractAdministrationController::userHasPermission() that fails to terminate execution after sending a forbidden response. Attackers can access all permission-protected admin pages by requesting their URLs… | ||
| CVE-2026-45008 | Med | 0.35 | 6.5 | 0.00 | May 15, 2026 | phpMyFAQ before 4.1.2 contains a path traversal vulnerability in Client::deleteClientFolder that allows admins with INSTANCE_DELETE permission to delete arbitrary directories. Attackers can submit traversal sequences like https://../../../ in the client URL parameter to… | ||
| CVE-2024-24574 | Med | 0.35 | 6.5 | 0.01 | Feb 5, 2024 | phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Unsafe echo of filename in phpMyFAQ\phpmyfaq\admin\attachments.php leads to allowed execution of JavaScript code in client side (XSS). This vulnerability has been patched in… | ||
| CVE-2024-22208 | Med | 0.35 | 6.5 | 0.01 | Feb 5, 2024 | phpMyFAQ is an Open Source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The 'sharing FAQ' functionality allows any unauthenticated actor to misuse the phpMyFAQ application to send arbitrary emails to a large range of targets. The phpMyFAQ… | ||
| CVE-2023-0792 | Med | 0.35 | 6.5 | 0.01 | Feb 12, 2023 | Code Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11. | ||
| CVE-2004-2257 | Med | 0.35 | 5.3 | 0.02 | Dec 31, 2004 | phpMyFAQ 1.4.0 allows remote attackers to access the Image Manager to upload or delete images without authorization via a direct request. |
- risk 0.40cvss 7.2epss 0.01
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The category image upload function in phpmyfaq is vulnerable to manipulation of the `Content-type` and `lang` parameters, allowing attackers to upload malicious files with a…
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in MiniCMS 1.10. There is a post.php?date= XSS vulnerability.
- risk 0.40cvss 6.1epss 0.01
In phpMyFaq before 2.9.9, there is XSS in admin/tags.main.php via a crafted tag.
- risk 0.40cvss 6.1epss 0.01
inc/PMF/Faq.php in phpMyFAQ before 2.9.7 has XSS in the question field.
- risk 0.39cvss —epss 0.00
phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows authenticated attackers to change account passwords without verifying the current password. Attackers with session access can submit a PUT request to…
- risk 0.39cvss —epss 0.00
phpMyFAQ before 4.1.8 contains an authentication bypass vulnerability in its two-factor authentication (TOTP) disable functionality. The removeTwofactorConfig() handler (reachable via POST /api/user/remove-twofactor) verifies only that the user is logged in and that a valid CSRF…
- risk 0.39cvss 7.1epss 0.01
Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
- risk 0.38cvss —epss 0.00
phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA protection and submit unlimited questions directly, causing database pollution and triggering outgoing…
- risk 0.38cvss 6.9epss 0.00
phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in search.twig where result.question and result.answerPreview are rendered with the raw filter, disabling autoescape protection. Attackers with FAQ editor privileges can inject HTML-entity-encoded…
- risk 0.38cvss 5.4epss 0.02
In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment.
- risk 0.36cvss 6.1epss 0.05
Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.9.
- risk 0.36cvss 6.1epss 0.06
Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8.
- risk 0.35cvss 6.5epss 0.00
phpMyFAQ before 4.1.6 does not adequately sanitize HTML in FAQ answers before generating PDFs via TCPDF. An attacker with permission to create or edit FAQ content can embed an tag whose src references a local file under the web root's content/ directory (e.g.,…
- risk 0.35cvss 6.5epss 0.00
phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryController. CVE-2026-24421 addressed this in the BackupController by adding: $this->userHasPermission(PermissionType::BACKUP). The same fix was not applied to 4…
- risk 0.35cvss 6.5epss 0.00
phpMyFAQ before 4.1.2 contains an authorization bypass vulnerability in AbstractAdministrationController::userHasPermission() that fails to terminate execution after sending a forbidden response. Attackers can access all permission-protected admin pages by requesting their URLs…
- risk 0.35cvss 6.5epss 0.00
phpMyFAQ before 4.1.2 contains a path traversal vulnerability in Client::deleteClientFolder that allows admins with INSTANCE_DELETE permission to delete arbitrary directories. Attackers can submit traversal sequences like https://../../../ in the client URL parameter to…
- risk 0.35cvss 6.5epss 0.01
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Unsafe echo of filename in phpMyFAQ\phpmyfaq\admin\attachments.php leads to allowed execution of JavaScript code in client side (XSS). This vulnerability has been patched in…
- risk 0.35cvss 6.5epss 0.01
phpMyFAQ is an Open Source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The 'sharing FAQ' functionality allows any unauthenticated actor to misuse the phpMyFAQ application to send arbitrary emails to a large range of targets. The phpMyFAQ…
- risk 0.35cvss 6.5epss 0.01
Code Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
- risk 0.35cvss 5.3epss 0.02
phpMyFAQ 1.4.0 allows remote attackers to access the Image Manager to upload or delete images without authorization via a direct request.
Page 4 of 10