CVE-2024-56199
- EPSS 0.26%
- Published 02.01.2025 18:15:20
- Last modified 14.08.2025 17:54:26
phpMyFAQ is an open source FAQ web application. Starting no later than version 3.2.10 and prior to version 4.0.2, an attacker can inject malicious HTML content into the FAQ editor at `http[:]//localhost/admin/index[.]php?action=editentry`, resulting ...
CVE-2024-55889
- EPSS 1.87%
- Published 13.12.2024 14:15:22
- Last modified 14.08.2025 18:56:50
phpMyFAQ is an open source FAQ web application. Prior to version 3.2.10, a vulnerability exists in the FAQ Record component where a privileged attacker can trigger a file download on a victim's machine upon page visit by embedding it in an <iframe> e...
CVE-2024-54141
- EPSS 0.23%
- Published 06.12.2024 15:15:09
- Last modified 15.08.2025 18:44:17
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Prior to 4.0.0, phpMyFAQ exposes the database (ie postgreSQL) server's credential when connection to DB fails. This vulnerability is fixed in 4.0.0...
CVE-2024-29196
- EPSS 0.46%
- Published 26.03.2024 03:15:13
- Last modified 09.01.2025 16:58:38
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. There is a Path Traversal vulnerability in Attachments that allows attackers with admin rights to upload malicious files to other locations of the ...
CVE-2024-29179
- EPSS 0.29%
- Published 25.03.2024 21:15:47
- Last modified 09.01.2025 16:59:41
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. An attacker with admin privileges can upload an attachment containing JS code without extension and the application will render it as HTML which al...
CVE-2024-28105
- EPSS 4.07%
- Published 25.03.2024 19:15:58
- Last modified 09.01.2025 17:14:59
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The category image upload function in phpmyfaq is vulnerable to manipulation of the `Content-type` and `lang` parameters, allowing attackers to upl...
CVE-2024-28106
- EPSS 0.16%
- Published 25.03.2024 19:15:58
- Last modified 09.01.2025 17:30:11
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. By manipulating the news parameter in a POST request, an attacker can inject malicious JavaScript code. Upon browsing to the compromised news page,...
CVE-2024-28107
- EPSS 0.61%
- Published 25.03.2024 19:15:58
- Last modified 09.01.2025 17:01:02
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. A SQL injection vulnerability has been discovered in the `insertentry` & `saveentry` when modifying records due to improper escaping of the email ...
CVE-2024-28108
- EPSS 0.63%
- Published 25.03.2024 19:15:58
- Last modified 09.01.2025 17:00:12
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Due to insufficient validation on the `contentLink` parameter, it is possible for unauthenticated users to inject HTML code to the page which might...
CVE-2024-27299
- EPSS 1.87%
- Published 25.03.2024 19:15:57
- Last modified 09.01.2025 17:27:11
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. A SQL injection vulnerability has been discovered in the the "Add News" functionality due to improper escaping of the email address. This allows an...