VYPR

Phpmyfaq

by PhpMyAdmin

Source repositories

CVEs (192)

  • CVE-2014-6050MedAug 28, 2018
    risk 0.31cvss 5.3epss 0.05

    phpMyFAQ before 2.8.13 allows remote attackers to bypass the CAPTCHA protection mechanism by replaying the request.

  • CVE-2014-6048MedAug 28, 2018
    risk 0.31cvss 5.3epss 0.06

    phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request.

  • CVE-2014-6047MedAug 28, 2018
    risk 0.31cvss 5.3epss 0.06

    phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by leveraging incorrect "download an attachment" permission checks.

  • CVE-2017-15728MedOct 22, 2017
    risk 0.31cvss 4.8epss 0.01

    In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via metaDescription or metaKeywords.

  • CVE-2024-22202MedFeb 5, 2024
    risk 0.30cvss 5.7epss 0.01

    phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. phpMyFAQ's user removal page allows an attacker to spoof another user's detail, and in turn make a compelling phishing case for removing another user's account. The front-end…

  • CVE-2023-5866MedOct 31, 2023
    risk 0.30cvss 5.7epss 0.00

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.2.1.

  • CVE-2024-27300MedMar 25, 2024
    risk 0.29cvss 5.5epss 0.01

    phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The `email` field in phpMyFAQ's user control panel page is vulnerable to stored XSS attacks due to the inadequacy of PHP's `FILTER_VALIDATE_EMAIL` function, which only…

  • CVE-2023-1753MedMar 31, 2023
    risk 0.29cvss 5.5epss 0.01

    Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

  • CVE-2026-85593MedSep 4, 2026
    risk 0.28cvss 5.4epss 0.00

    phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting vulnerability in FaqHelper::convertOldInternalLinks() that calls html_entity_decode() on sanitized FAQ content, reversing entity-encoding protection. Authenticated users with FAQ editing privileges can inject…

  • CVE-2026-76209MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    phpMyFAQ versions before v4.1.6 fail to validate the security.enableRegistration setting in API endpoints, allowing attackers to create user accounts when registration is disabled. Attackers can bypass the registration restriction by submitting requests to POST /api/register or…

  • CVE-2026-46365MedMay 15, 2026
    risk 0.28cvss 5.4epss 0.00

    phpMyFAQ before 4.1.2 contains a missing authorization vulnerability in the DELETE /admin/api/content/tags/{tagId} endpoint that allows any authenticated user to delete tags. Any logged-in user, including regular frontend users, can delete arbitrary tags by sending a DELETE…

  • CVE-2026-46363MedMay 15, 2026
    risk 0.28cvss 5.4epss 0.00

    phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in FAQ creation and update endpoints that bypass sanitization through encode-decode cycles. The vulnerability allows authenticated attackers with FAQ_ADD permission to inject malicious script tags via…

  • CVE-2026-46360MedMay 15, 2026
    risk 0.28cvss 5.4epss 0.00

    phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in SvgSanitizer::decodeAllEntities() that limits recursive entity decoding to 5 iterations, allowing attackers to bypass sanitization. Authenticated users with FAQ_EDIT permission can upload malicious SVG…

  • CVE-2026-34974MedApr 2, 2026
    risk 0.28cvss 5.4epss 0.00

    phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the regex-based SVG sanitizer in phpMyFAQ (SvgSanitizer.php) can be bypassed using HTML entity encoding in javascript: URLs within SVG attributes. Any user with edit_faq permission can upload a…

  • CVE-2025-68951MedDec 29, 2025
    risk 0.28cvss 5.4epss 0.00

    phpMyFAQ is an open source FAQ web application. Versions 4.0.14 and 4.0.15 have a stored cross-site scripting (XSS) vulnerability that allows an attacker to execute arbitrary JavaScript in an administrator’s browser by registering a user whose display name contains HTML…

  • CVE-2024-55889MedDec 13, 2024
    risk 0.28cvss 4.9epss 0.02

    phpMyFAQ is an open source FAQ web application. Prior to version 3.2.10, a vulnerability exists in the FAQ Record component where a privileged attacker can trigger a file download on a victim's machine upon page visit by embedding it in an element without user…

  • CVE-2023-6890MedDec 16, 2023
    risk 0.28cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.17.

  • CVE-2023-6889MedDec 16, 2023
    risk 0.28cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.17.

  • CVE-2023-5867MedOct 31, 2023
    risk 0.28cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.2.

  • CVE-2023-5319MedSep 30, 2023
    risk 0.28cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.18.

Page 6 of 10