Phpmyfaq

Phpmyfaq

159 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.48%
  • Veröffentlicht 11.12.2022 15:15:10
  • Zuletzt bearbeitet 21.11.2024 07:35:12

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.9.

Exploit
  • EPSS 0.42%
  • Veröffentlicht 11.12.2022 15:15:10
  • Zuletzt bearbeitet 21.11.2024 07:35:12

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.1.9.

Exploit
  • EPSS 0.54%
  • Veröffentlicht 31.10.2022 11:15:10
  • Zuletzt bearbeitet 21.11.2024 07:20:12

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

Exploit
  • EPSS 5.91%
  • Veröffentlicht 31.10.2022 11:15:10
  • Zuletzt bearbeitet 16.02.2026 15:18:33

Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

Exploit
  • EPSS 1.17%
  • Veröffentlicht 29.10.2022 13:15:09
  • Zuletzt bearbeitet 21.11.2024 07:20:10

Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

Exploit
  • EPSS 0.98%
  • Veröffentlicht 19.10.2022 13:15:08
  • Zuletzt bearbeitet 21.11.2024 07:19:52

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.0-alpha.

  • EPSS 0.5%
  • Veröffentlicht 07.09.2018 05:29:00
  • Zuletzt bearbeitet 21.11.2024 03:53:08

phpMyFAQ before 2.9.11 allows CSRF.

  • EPSS 1.37%
  • Veröffentlicht 07.09.2018 05:29:00
  • Zuletzt bearbeitet 21.11.2024 03:53:08

The admin backend in phpMyFAQ before 2.9.11 allows CSV injection in reports.

  • EPSS 5.68%
  • Veröffentlicht 28.08.2018 17:29:01
  • Zuletzt bearbeitet 21.11.2024 02:13:41

phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by leveraging incorrect "download an attachment" permission checks.

  • EPSS 5.68%
  • Veröffentlicht 28.08.2018 17:29:01
  • Zuletzt bearbeitet 21.11.2024 02:13:41

phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request.