VYPR

Phpmyfaq

by PhpMyAdmin

Source repositories

CVEs (170)

  • CVE-2023-2999MedMay 31, 2023
    risk 0.33cvss 6.1epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14.

  • CVE-2023-2998MedMay 31, 2023
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14.

  • CVE-2023-1884MedApr 5, 2023
    risk 0.33cvss 6.1epss 0.00

    Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

  • CVE-2023-1880MedApr 5, 2023
    risk 0.33cvss 6.1epss 0.02

    Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

  • CVE-2023-0314MedJan 15, 2023
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.10.

  • CVE-2023-0312MedJan 15, 2023
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.10.

  • CVE-2024-29179MedMar 25, 2024
    risk 0.31cvss 4.8epss 0.01

    phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. An attacker with admin privileges can upload an attachment containing JS code without extension and the application will render it as HTML which allows for XSS attacks.

  • CVE-2014-6050MedAug 28, 2018
    risk 0.31cvss 5.3epss 0.05

    phpMyFAQ before 2.8.13 allows remote attackers to bypass the CAPTCHA protection mechanism by replaying the request.

  • CVE-2014-6048MedAug 28, 2018
    risk 0.31cvss 5.3epss 0.06

    phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request.

  • CVE-2014-6047MedAug 28, 2018
    risk 0.31cvss 5.3epss 0.06

    phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by leveraging incorrect "download an attachment" permission checks.

  • CVE-2017-15728MedOct 22, 2017
    risk 0.31cvss 4.8epss 0.01

    In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via metaDescription or metaKeywords.

  • CVE-2024-22202MedFeb 5, 2024
    risk 0.30cvss 5.7epss 0.01

    phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. phpMyFAQ's user removal page allows an attacker to spoof another user's detail, and in turn make a compelling phishing case for removing another user's account. The front-end…

  • CVE-2023-5866MedOct 31, 2023
    risk 0.30cvss 5.7epss 0.00

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.2.1.

  • CVE-2024-27300MedMar 25, 2024
    risk 0.29cvss 5.5epss 0.01

    phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The `email` field in phpMyFAQ's user control panel page is vulnerable to stored XSS attacks due to the inadequacy of PHP's `FILTER_VALIDATE_EMAIL` function, which only…

  • CVE-2023-1753MedMar 31, 2023
    risk 0.29cvss 5.5epss 0.01

    Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

  • CVE-2026-46365MedMay 15, 2026
    risk 0.28cvss 5.4epss 0.00

    phpMyFAQ before 4.1.2 contains a missing authorization vulnerability in the DELETE /admin/api/content/tags/{tagId} endpoint that allows any authenticated user to delete tags. Any logged-in user, including regular frontend users, can delete arbitrary tags by sending a DELETE…

  • CVE-2026-46363MedMay 15, 2026
    risk 0.28cvss 5.4epss 0.00

    phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in FAQ creation and update endpoints that bypass sanitization through encode-decode cycles. The vulnerability allows authenticated attackers with FAQ_ADD permission to inject malicious script tags via…

  • CVE-2026-46360MedMay 15, 2026
    risk 0.28cvss 5.4epss 0.00

    phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in SvgSanitizer::decodeAllEntities() that limits recursive entity decoding to 5 iterations, allowing attackers to bypass sanitization. Authenticated users with FAQ_EDIT permission can upload malicious SVG…

  • CVE-2026-34974MedApr 2, 2026
    risk 0.28cvss 5.4epss 0.00

    phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the regex-based SVG sanitizer in phpMyFAQ (SvgSanitizer.php) can be bypassed using HTML entity encoding in javascript: URLs within SVG attributes. Any user with edit_faq permission can upload a…

  • CVE-2025-68951MedDec 29, 2025
    risk 0.28cvss 5.4epss 0.00

    phpMyFAQ is an open source FAQ web application. Versions 4.0.14 and 4.0.15 have a stored cross-site scripting (XSS) vulnerability that allows an attacker to execute arbitrary JavaScript in an administrator’s browser by registering a user whose display name contains HTML…

Page 5 of 9