VYPR

Phpmyfaq

by PhpMyAdmin

Source repositories

CVEs (170)

  • CVE-2017-15727MedOct 22, 2017
    risk 0.38cvss 5.4epss 0.02

    In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment.

  • CVE-2022-4407MedDec 11, 2022
    risk 0.36cvss 6.1epss 0.04

    Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.9.

  • CVE-2022-3766MedOct 31, 2022
    risk 0.36cvss 6.1epss 0.06

    Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

  • CVE-2026-49205MedJun 18, 2026
    risk 0.35cvss 6.5epss 0.00

    phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryController. CVE-2026-24421 addressed this in the BackupController by adding: $this->userHasPermission(PermissionType::BACKUP). The same fix was not applied to 4…

  • CVE-2026-46362MedMay 15, 2026
    risk 0.35cvss 6.5epss 0.00

    phpMyFAQ before 4.1.2 contains an authorization bypass vulnerability in AbstractAdministrationController::userHasPermission() that fails to terminate execution after sending a forbidden response. Attackers can access all permission-protected admin pages by requesting their URLs…

  • CVE-2026-45008MedMay 15, 2026
    risk 0.35cvss 6.5epss 0.00

    phpMyFAQ before 4.1.2 contains a path traversal vulnerability in Client::deleteClientFolder that allows admins with INSTANCE_DELETE permission to delete arbitrary directories. Attackers can submit traversal sequences like https://../../../ in the client URL parameter to…

  • CVE-2024-24574MedFeb 5, 2024
    risk 0.35cvss 6.5epss 0.01

    phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Unsafe echo of filename in phpMyFAQ\phpmyfaq\admin\attachments.php leads to allowed execution of JavaScript code in client side (XSS). This vulnerability has been patched in…

  • CVE-2024-22208MedFeb 5, 2024
    risk 0.35cvss 6.5epss 0.01

    phpMyFAQ is an Open Source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The 'sharing FAQ' functionality allows any unauthenticated actor to misuse the phpMyFAQ application to send arbitrary emails to a large range of targets. The phpMyFAQ…

  • CVE-2023-0792MedFeb 12, 2023
    risk 0.35cvss 6.5epss 0.01

    Code Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

  • CVE-2004-2257MedDec 31, 2004
    risk 0.35cvss 5.3epss 0.02

    phpMyFAQ 1.4.0 allows remote attackers to access the Image Manager to upload or delete images without authorization via a direct request.

  • CVE-2026-34973MedApr 2, 2026
    risk 0.34cvss 5.3epss 0.00

    phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the searchCustomPages() method in phpmyfaq/src/phpMyFAQ/Search.php uses real_escape_string() (via escape()) to sanitize the search term before embedding it in LIKE clauses. However, real_escape_string() does…

  • CVE-2026-24422MedJan 24, 2026
    risk 0.34cvss 5.3epss 0.00

    phpMyFAQ is an open source FAQ web application. In versions 4.0.16 and below, multiple public API endpoints improperly expose sensitive user information due to insufficient access controls. The OpenQuestionController::list() endpoint calls Question::getAll() with showAll=true by…

  • CVE-2023-1885MedApr 5, 2023
    risk 0.34cvss 6.3epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

  • CVE-2023-1761MedMar 31, 2023
    risk 0.34cvss 6.3epss 0.00

    Cross-site Scripting in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

  • CVE-2017-14618MedSep 20, 2017
    risk 0.34cvss 4.8epss 0.02

    Cross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the Questions field in an "Add New FAQ" action.

  • CVE-2026-34729MedApr 2, 2026
    risk 0.33cvss 6.1epss 0.00

    phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, there is a stored XSS vulnerability via Regex Bypass in Filter::removeAttributes(). This issue has been patched in version 4.1.1.

  • CVE-2026-32629MedApr 2, 2026
    risk 0.33cvss 6.1epss 0.00

    phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, an unauthenticated attacker can submit a guest FAQ with an email address that is syntactically valid per RFC 5321 (quoted local part) yet contains raw HTML — for example…

  • CVE-2023-5863MedOct 31, 2023
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.2.2.

  • CVE-2023-5320MedSep 30, 2023
    risk 0.33cvss 6.1epss 0.00

    Cross-site Scripting (XSS) - DOM in GitHub repository thorsten/phpmyfaq prior to 3.1.18.

  • CVE-2023-5316MedSep 30, 2023
    risk 0.33cvss 6.1epss 0.00

    Cross-site Scripting (XSS) - DOM in GitHub repository thorsten/phpmyfaq prior to 3.1.18.

Page 4 of 9