thorsten/phpmyfaq
Packagist112 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting thorsten/phpmyfaqpage 3 of 3
- CVE-2026-46366HIGHCVSS 7.5EG 7.5fixed in 4.1.22026-05-15
vulnerable: 2.10.0-alpha ... 4.1.1 (170 versions)
phpMyFAQ before 4.1.2 contains an information disclosure vulnerability in the getIdFromSolutionId() method that lacks permission filtering, allowing unauthenticated attackers to enumerate restricted FAQ entries and read their titles via th…
- CVE-2026-46367HIGHCVSS 7.6EG 7.6fixed in 4.1.22026-05-15
vulnerable: 4.1.1
phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in Utils::parseUrl() that allows authenticated users to inject JavaScript via malformed URLs in comments. Attackers can craft URLs with unescaped quotes to inject e…
- CVE-2026-47132MEDIUMCVSS 5.4EG 5.4fixed in 4.2.0-alpha2026-08-12
vulnerable: 2.10.0-alpha ... 4.1.8 (177 versions)
phpMyFAQ is an open source FAQ web application. Prior to version 4.2.0-alpha, an authenticated SQL LIKE wildcard injection vulnerability in phpMyFAQ’s chat user search allows any logged-in user to bypass the intended display-name search …
- CVE-2026-48488LOWCVSS 2.7EG 2.7fixed in 4.1.42026-06-08
vulnerable: 2.10.0-alpha ... 4.1.3 (172 versions)
phpMyFAQ is an open source FAQ web application. Prior to version 4.1.4, attachment passwords are hashed using SHA-1, a cryptographically broken algorithm. SHA-1 has been vulnerable to collision attacks since 2017 (SHAttered). Version 4.1.4…
- CVE-2026-49205MEDIUMCVSS 6.5EG 6.5fixed in 4.1.42026-06-18
vulnerable: 2.10.0-alpha ... 4.1.3 (172 versions)
phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryController. CVE-2026-24421 addressed this in the BackupController by adding: $this->userHasPermission(PermissionType::BA…
- CVE-2026-56396HIGHCVSS 8.8EG 8.8fixed in 4.1.42026-06-21
vulnerable: 2.10.0-alpha ... 4.1.3 (172 versions)
phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin users with edit_user permission can set is_s…
- CVE-2026-56736HIGHCVSS 8.2EG 8.2fixed in 4.2.0-alpha2026-09-24
vulnerable: 2.10.0-alpha ... 4.1.8 (177 versions)
phpMyFAQ is an open source FAQ web application. A stored cross-site scripting (XSS) vulnerability in versions prior to 4.2.0-alpha allows any unauthenticated user (or low-privileged registered user) to inject arbitrary JavaScript that exec…
- CVE-2026-56737HIGHCVSS 8.1EG 8.1fixed in 4.1.62026-09-24
vulnerable: 3.2.0 ... 4.1.5 (58 versions)
phpMyFAQ is an open source FAQ web application. Versions 3.2.0 through 4.1.5 contain an authentication bypass in its public two-factor authentication verification flow: an unauthenticated attacker can submit an account’s numeric user ID …
- CVE-2026-56738HIGHCVSS 8.5EG 8.5fixed in 4.1.62026-09-24
vulnerable: 2.10.0-alpha ... 4.1.5 (174 versions)
phpMyFAQ is an open source FAQ web application. The `StopWords::add()` method inversions prior to 4.1.6 builds a SQL `INSERT` statement using `sprintf()` and inserts the user-supplied stop word value directly into the query string without …
- CVE-2026-57961LOWCVSS 2.7EG 2.7fixed in 4.1.52026-07-10
vulnerable: 4.0.0 ... 4.1.4 (46 versions)
phpMyFAQ before 4.1.5 contains a potential authenticated path traversal vulnerability in the concatenatePaths() function within src/phpMyFAQ/Export/Pdf/Wrapper.php. A user with FAQ editing privileges can store HTML containing crafted image…
- CVE-2026-57994MEDIUMCVSS 5.3EG 5.3fixed in 4.1.52026-07-10
vulnerable: 4.1.0, 4.1.1, 4.1.2, 4.1.3, 4.1.4
phpMyFAQ before 4.1.5 applies inconsistent active=yes and publication-date filtering across its public FAQ API endpoints, allowing unauthenticated attackers to retrieve inactive (draft or review-only) FAQ content. Specifically, GET /api/v3…
- CVE-2026-57995HIGHCVSS 8.8EG 8.8fixed in 4.1.52026-07-01
vulnerable: 2.10.0-alpha ... 4.1.4 (173 versions)
phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that allows GROUP_EDIT administrators to grant arbitrary rights to groups without verifying they hold those rights themselves. A dele…
Check whether thorsten/phpmyfaq is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for thorsten/phpmyfaq CVEs against the assets you own.
Book a Demo →