CVE-2017-15731
- EPSS 0.59%
- Veröffentlicht 22.10.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.adminlog.php.
CVE-2017-15732
- EPSS 0.58%
- Veröffentlicht 22.10.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/news.php.
CVE-2017-15733
- EPSS 0.58%
- Veröffentlicht 22.10.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/ajax.attachment.php and admin/att.main.php.
CVE-2017-15734
- EPSS 1.1%
- Veröffentlicht 22.10.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php.
CVE-2017-15735
- EPSS 1.1%
- Veröffentlicht 22.10.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary.
CVE-2017-14618
- EPSS 2.43%
- Veröffentlicht 20.09.2017 21:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Cross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the Questions field in an "Add New FAQ" action.
CVE-2017-14619
- EPSS 2.17%
- Veröffentlicht 20.09.2017 21:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Cross-site scripting (XSS) vulnerability in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the "Title of your FAQ" field in the Configuration Module.
CVE-2017-11187
- EPSS 1.05%
- Veröffentlicht 12.07.2017 14:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
phpMyFAQ before 2.9.8 does not properly mitigate brute-force attacks that try many passwords in attempted logins quickly.
CVE-2017-7579
- EPSS 0.67%
- Veröffentlicht 07.04.2017 16:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
inc/PMF/Faq.php in phpMyFAQ before 2.9.7 has XSS in the question field.
CVE-2014-0813
- EPSS 1.07%
- Veröffentlicht 14.02.2014 16:55:13
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site request forgery (CSRF) vulnerability in phpMyFAQ before 2.8.6 allows remote attackers to hijack the authentication of arbitrary users for requests that modify settings.