VYPR

Phpmyfaq

by PhpMyAdmin

Source repositories

CVEs (192)

  • CVE-2026-85589MedSep 4, 2026
    risk 0.27cvss —epss 0.00

    phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerability in the admin dashboard API endpoints searches and content-health that enforce only authentication without permission checks. Any authenticated user can access these endpoints to read site-wide search…

  • CVE-2026-85588MedSep 4, 2026
    risk 0.27cvss —epss 0.00

    phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attackers obtaining exported archives can extract the TOTP seed and generate valid one-time codes to bypass two-factor authentication.

  • CVE-2026-85587MedSep 4, 2026
    risk 0.27cvss —epss 0.00

    phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content. Attackers with only add permissions can access news edit and FAQ translate endpoints to view unpublished content invisible to…

  • CVE-2026-76215MedAug 19, 2026
    risk 0.27cvss 5.3epss 0.00

    phpMyFAQ before 4.1.7 fails to apply parent FAQ visibility checks before returning child resources including comments and attachments. Unauthenticated attackers can retrieve restricted comment text, commenter email addresses, and attachment filenames for FAQ records they cannot…

  • CVE-2026-76212MedAug 19, 2026
    risk 0.27cvss 5.3epss 0.00

    phpMyFAQ before 4.1.7, when configured to use PostgreSQL via the native pgsql PHP extension, declares an incorrect LIKE ESCAPE character ('=') in the Search/Database/Pgsql.php backend while escapeLikeWildcards() escapes user input with the '|' prefix. As a result, wildcard…

  • CVE-2024-56199MedJan 2, 2025
    risk 0.27cvss 5.2epss 0.00

    phpMyFAQ is an open source FAQ web application. Starting no later than version 3.2.10 and prior to version 4.0.2, an attacker can inject malicious HTML content into the FAQ editor at `http[:]//localhost/admin/index[.]php?action=editentry`, resulting in a complete disruption of…

  • CVE-2024-28108MedMar 25, 2024
    risk 0.24cvss 4.7epss 0.01

    phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Due to insufficient validation on the `contentLink` parameter, it is possible for unauthenticated users to inject HTML code to the page which might affect other users. _Also,…

  • CVE-2023-5864MedOct 31, 2023
    risk 0.24cvss 4.8epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.1.

  • CVE-2023-3469MedJun 30, 2023
    risk 0.24cvss 4.8epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.2.0-beta.2.

  • CVE-2023-2550MedMay 5, 2023
    risk 0.24cvss 4.8epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.13.

  • CVE-2023-2427MedMay 5, 2023
    risk 0.24cvss 4.8epss 0.00

    Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.13.

  • CVE-2023-1756MedApr 5, 2023
    risk 0.24cvss 4.7epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

  • CVE-2023-1760MedMar 31, 2023
    risk 0.24cvss 4.8epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

  • CVE-2023-1759MedMar 31, 2023
    risk 0.24cvss 4.8epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

  • CVE-2023-1754MedMar 31, 2023
    risk 0.24cvss 4.7epss 0.01

    Improper Neutralization of Input During Web Page Generation in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

  • CVE-2026-76211MedAug 19, 2026
    risk 0.21cvss 4.3epss 0.00

    phpMyFAQ before 4.1.7 fails to properly enforce CONFIGURATION_EDIT permission on admin API read endpoints for LDAP, Elasticsearch, OpenSearch, and dashboard configuration, allowing any authenticated user to access sensitive administrative data. Attackers can retrieve LDAP server…

  • CVE-2026-45009MedMay 15, 2026
    risk 0.21cvss 4.3epss 0.00

    phpMyFAQ before 4.1.2 contains an insufficient authorization vulnerability in admin-api routes that allows authenticated ordinary users to access administrative endpoints by only checking login status instead of verifying backend privileges. Attackers with valid frontend user…

  • CVE-2026-45007MedMay 15, 2026
    risk 0.21cvss 4.3epss 0.00

    phpMyFAQ before 4.1.2 contains missing permission checks in ConfigurationTabController.php where 12 endpoints use userIsAuthenticated() instead of userHasPermission(CONFIGURATION_EDIT). Any authenticated user can enumerate system configuration metadata including permission…

  • CVE-2024-28106MedMar 25, 2024
    risk 0.21cvss 4.3epss 0.01

    phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. By manipulating the news parameter in a POST request, an attacker can inject malicious JavaScript code. Upon browsing to the compromised news page, the XSS payload triggers.…

  • CVE-2023-1887MedApr 5, 2023
    risk 0.21cvss 4.3epss 0.01

    Business Logic Errors in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

Page 8 of 10