CVE-2026-76213
- EPSS 0.28%
- Veröffentlicht 19.08.2026 14:17:47
- Zuletzt bearbeitet 01.09.2026 15:20:20
phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two-factor authentication step where the failure counter is session-scoped and reset on each successful password re-authentication. Attackers with a valid password can bypass the five-...
CVE-2026-76214
- EPSS 0.29%
- Veröffentlicht 19.08.2026 14:17:47
- Zuletzt bearbeitet 01.09.2026 15:20:12
phpMyFAQ before 4.1.7 fails to persist the WebAuthn login challenge generated by prepareForLogin, because neither WebAuthn controller saves the mutated key objects back to the database. At login the anti-replay comparison is skipped by its own null g...
CVE-2026-76215
- EPSS 0.24%
- Veröffentlicht 19.08.2026 14:17:47
- Zuletzt bearbeitet 01.09.2026 15:20:04
phpMyFAQ before 4.1.7 fails to apply parent FAQ visibility checks before returning child resources including comments and attachments. Unauthenticated attackers can retrieve restricted comment text, commenter email addresses, and attachment filenames...
CVE-2026-76207
- EPSS 0.27%
- Veröffentlicht 19.08.2026 14:17:46
- Zuletzt bearbeitet 01.09.2026 15:23:15
phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me tokens are issued before 2FA verification completes. Attackers with valid credentials can obtain a remember-me cookie, skip the 2FA challenge, and repla...
CVE-2026-76208
- EPSS 0.25%
- Veröffentlicht 19.08.2026 14:17:46
- Zuletzt bearbeitet 30.09.2026 18:18:40
phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass vulnerability in AuthLdap::create(). When LDAP authentication is enabled, after a successful LDAP bind the code calls User::setStatus('active') unconditionally, which overwrites t...
CVE-2026-76209
- EPSS 0.22%
- Veröffentlicht 19.08.2026 14:17:46
- Zuletzt bearbeitet 01.09.2026 15:21:54
phpMyFAQ versions before v4.1.6 fail to validate the security.enableRegistration setting in API endpoints, allowing attackers to create user accounts when registration is disabled. Attackers can bypass the registration restriction by submitting reque...
CVE-2026-76210
- EPSS 0.29%
- Veröffentlicht 19.08.2026 14:17:46
- Zuletzt bearbeitet 01.09.2026 15:21:48
phpMyFAQ before 4.1.6 does not adequately sanitize HTML in FAQ answers before generating PDFs via TCPDF. An attacker with permission to create or edit FAQ content can embed an <img> tag whose src references a local file under the web root's content/ ...
CVE-2026-76211
- EPSS 0.2%
- Veröffentlicht 19.08.2026 14:17:46
- Zuletzt bearbeitet 01.09.2026 15:21:40
phpMyFAQ before 4.1.7 fails to properly enforce CONFIGURATION_EDIT permission on admin API read endpoints for LDAP, Elasticsearch, OpenSearch, and dashboard configuration, allowing any authenticated user to access sensitive administrative data. Attac...
CVE-2026-76212
- EPSS 0.3%
- Veröffentlicht 19.08.2026 14:17:46
- Zuletzt bearbeitet 01.09.2026 15:20:29
phpMyFAQ before 4.1.7, when configured to use PostgreSQL via the native pgsql PHP extension, declares an incorrect LIKE ESCAPE character ('=') in the Search/Database/Pgsql.php backend while escapeLikeWildcards() escapes user input with the '|' prefix...
CVE-2026-76205
- EPSS 0.23%
- Veröffentlicht 19.08.2026 14:17:45
- Zuletzt bearbeitet 01.09.2026 15:23:30
phpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the glossary create and update endpoints caused by truncating an escaped string before embedding it in a SQL literal. Authenticated users with glossary add or edit permissions can craft ...