Phpmyfaq
by PhpMyAdmin
Source repositories
CVEs (170)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-2999 | Med | 0.33 | 6.1 | 0.00 | May 31, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14. | ||
| CVE-2023-2998 | Med | 0.33 | 6.1 | 0.01 | May 31, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14. | ||
| CVE-2023-1884 | Med | 0.33 | 6.1 | 0.00 | Apr 5, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.12. | ||
| CVE-2023-1880 | Med | 0.33 | 6.1 | 0.02 | Apr 5, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.12. | ||
| CVE-2023-0314 | Med | 0.33 | 6.1 | 0.01 | Jan 15, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.10. | ||
| CVE-2023-0312 | Med | 0.33 | 6.1 | 0.01 | Jan 15, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.10. | ||
| CVE-2024-29179 | Med | 0.31 | 4.8 | 0.01 | Mar 25, 2024 | phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. An attacker with admin privileges can upload an attachment containing JS code without extension and the application will render it as HTML which allows for XSS attacks. | ||
| CVE-2014-6050 | Med | 0.31 | 5.3 | 0.05 | Aug 28, 2018 | phpMyFAQ before 2.8.13 allows remote attackers to bypass the CAPTCHA protection mechanism by replaying the request. | ||
| CVE-2014-6048 | Med | 0.31 | 5.3 | 0.06 | Aug 28, 2018 | phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request. | ||
| CVE-2014-6047 | Med | 0.31 | 5.3 | 0.06 | Aug 28, 2018 | phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by leveraging incorrect "download an attachment" permission checks. | ||
| CVE-2017-15728 | Med | 0.31 | 4.8 | 0.01 | Oct 22, 2017 | In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via metaDescription or metaKeywords. | ||
| CVE-2024-22202 | Med | 0.30 | 5.7 | 0.01 | Feb 5, 2024 | phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. phpMyFAQ's user removal page allows an attacker to spoof another user's detail, and in turn make a compelling phishing case for removing another user's account. The front-end… | ||
| CVE-2023-5866 | Med | 0.30 | 5.7 | 0.00 | Oct 31, 2023 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.2.1. | ||
| CVE-2024-27300 | Med | 0.29 | 5.5 | 0.01 | Mar 25, 2024 | phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The `email` field in phpMyFAQ's user control panel page is vulnerable to stored XSS attacks due to the inadequacy of PHP's `FILTER_VALIDATE_EMAIL` function, which only… | ||
| CVE-2023-1753 | Med | 0.29 | 5.5 | 0.01 | Mar 31, 2023 | Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.12. | ||
| CVE-2026-46365 | Med | 0.28 | 5.4 | 0.00 | May 15, 2026 | phpMyFAQ before 4.1.2 contains a missing authorization vulnerability in the DELETE /admin/api/content/tags/{tagId} endpoint that allows any authenticated user to delete tags. Any logged-in user, including regular frontend users, can delete arbitrary tags by sending a DELETE… | ||
| CVE-2026-46363 | Med | 0.28 | 5.4 | 0.00 | May 15, 2026 | phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in FAQ creation and update endpoints that bypass sanitization through encode-decode cycles. The vulnerability allows authenticated attackers with FAQ_ADD permission to inject malicious script tags via… | ||
| CVE-2026-46360 | Med | 0.28 | 5.4 | 0.00 | May 15, 2026 | phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in SvgSanitizer::decodeAllEntities() that limits recursive entity decoding to 5 iterations, allowing attackers to bypass sanitization. Authenticated users with FAQ_EDIT permission can upload malicious SVG… | ||
| CVE-2026-34974 | Med | 0.28 | 5.4 | 0.00 | Apr 2, 2026 | phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the regex-based SVG sanitizer in phpMyFAQ (SvgSanitizer.php) can be bypassed using HTML entity encoding in javascript: URLs within SVG attributes. Any user with edit_faq permission can upload a… | ||
| CVE-2025-68951 | Med | 0.28 | 5.4 | 0.00 | Dec 29, 2025 | phpMyFAQ is an open source FAQ web application. Versions 4.0.14 and 4.0.15 have a stored cross-site scripting (XSS) vulnerability that allows an attacker to execute arbitrary JavaScript in an administrator’s browser by registering a user whose display name contains HTML… |
- risk 0.33cvss 6.1epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14.
- risk 0.33cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14.
- risk 0.33cvss 6.1epss 0.00
Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
- risk 0.33cvss 6.1epss 0.02
Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
- risk 0.33cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.10.
- risk 0.33cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.10.
- risk 0.31cvss 4.8epss 0.01
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. An attacker with admin privileges can upload an attachment containing JS code without extension and the application will render it as HTML which allows for XSS attacks.
- risk 0.31cvss 5.3epss 0.05
phpMyFAQ before 2.8.13 allows remote attackers to bypass the CAPTCHA protection mechanism by replaying the request.
- risk 0.31cvss 5.3epss 0.06
phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request.
- risk 0.31cvss 5.3epss 0.06
phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by leveraging incorrect "download an attachment" permission checks.
- risk 0.31cvss 4.8epss 0.01
In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via metaDescription or metaKeywords.
- risk 0.30cvss 5.7epss 0.01
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. phpMyFAQ's user removal page allows an attacker to spoof another user's detail, and in turn make a compelling phishing case for removing another user's account. The front-end…
- risk 0.30cvss 5.7epss 0.00
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.2.1.
- risk 0.29cvss 5.5epss 0.01
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The `email` field in phpMyFAQ's user control panel page is vulnerable to stored XSS attacks due to the inadequacy of PHP's `FILTER_VALIDATE_EMAIL` function, which only…
- risk 0.29cvss 5.5epss 0.01
Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
- risk 0.28cvss 5.4epss 0.00
phpMyFAQ before 4.1.2 contains a missing authorization vulnerability in the DELETE /admin/api/content/tags/{tagId} endpoint that allows any authenticated user to delete tags. Any logged-in user, including regular frontend users, can delete arbitrary tags by sending a DELETE…
- risk 0.28cvss 5.4epss 0.00
phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in FAQ creation and update endpoints that bypass sanitization through encode-decode cycles. The vulnerability allows authenticated attackers with FAQ_ADD permission to inject malicious script tags via…
- risk 0.28cvss 5.4epss 0.00
phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in SvgSanitizer::decodeAllEntities() that limits recursive entity decoding to 5 iterations, allowing attackers to bypass sanitization. Authenticated users with FAQ_EDIT permission can upload malicious SVG…
- risk 0.28cvss 5.4epss 0.00
phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the regex-based SVG sanitizer in phpMyFAQ (SvgSanitizer.php) can be bypassed using HTML entity encoding in javascript: URLs within SVG attributes. Any user with edit_faq permission can upload a…
- risk 0.28cvss 5.4epss 0.00
phpMyFAQ is an open source FAQ web application. Versions 4.0.14 and 4.0.15 have a stored cross-site scripting (XSS) vulnerability that allows an attacker to execute arbitrary JavaScript in an administrator’s browser by registering a user whose display name contains HTML…
Page 5 of 9