Phpmyfaq

Phpmyfaq

159 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 19.08.2026 14:17:45
  • Zuletzt bearbeitet 01.09.2026 15:23:23

phpMyFAQ versions before 4.1.7 fail to validate active status in the PDF export endpoint, allowing unauthenticated attackers to retrieve draft FAQ metadata. Attackers can access the public PDF export route with sequential FAQ identifiers to obtain ti...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 19.08.2026 14:17:42
  • Zuletzt bearbeitet 01.09.2026 15:30:06

phpMyFAQ before 4.1.7 stores password reset tokens in a publicly accessible tracking file when user tracking is enabled. Unauthenticated attackers can read the tracking file at content/core/data/trackingDDMMYYYY to extract reset tokens and replay the...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 19.08.2026 14:17:42
  • Zuletzt bearbeitet 01.09.2026 16:05:11

phpMyFAQ before 4.1.7 contains an authentication bypass vulnerability in SetupController that allows unauthenticated attackers to run database migrations and create configuration backups when maintenance mode is enabled. Attackers can call POST /api/...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 19.08.2026 14:17:42
  • Zuletzt bearbeitet 01.09.2026 16:05:18

phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at content.zip, exposing sensitive files including database credentials. Unauthenticated attackers can race concurrent requests to download the temporary ZI...

  • EPSS 0.25%
  • Veröffentlicht 15.07.2026 11:25:33
  • Zuletzt bearbeitet 16.07.2026 16:19:14

phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that allows non-SuperAdmin administrators to create SuperAdmin accounts. A delegated administrator with USER_ADD/EDIT/DELETE permissions can call POST /a...

  • EPSS 0.27%
  • Veröffentlicht 10.07.2026 13:58:00
  • Zuletzt bearbeitet 10.07.2026 17:41:47

phpMyFAQ before 4.1.5 contains a potential authenticated path traversal vulnerability in the concatenatePaths() function within src/phpMyFAQ/Export/Pdf/Wrapper.php. A user with FAQ editing privileges can store HTML containing crafted image paths that...

  • EPSS 0.21%
  • Veröffentlicht 10.07.2026 13:58:00
  • Zuletzt bearbeitet 10.07.2026 17:41:47

phpMyFAQ before 4.1.5 applies inconsistent active=yes and publication-date filtering across its public FAQ API endpoints, allowing unauthenticated attackers to retrieve inactive (draft or review-only) FAQ content. Specifically, GET /api/v3.1/faq/{cat...

  • EPSS 0.33%
  • Veröffentlicht 30.06.2026 22:08:42
  • Zuletzt bearbeitet 02.07.2026 17:48:43

phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that allows GROUP_EDIT administrators to grant arbitrary rights to groups without verifying they hold those rights themselves. A delegated admin...

  • EPSS 0.44%
  • Veröffentlicht 21.06.2026 13:27:03
  • Zuletzt bearbeitet 23.06.2026 15:16:39

phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin users with edit_user permission can set is_superadmin f...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 02.04.2026 14:48:22
  • Zuletzt bearbeitet 24.07.2026 21:10:00

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the regex-based SVG sanitizer in phpMyFAQ (SvgSanitizer.php) can be bypassed using HTML entity encoding in javascript: URLs within SVG <a href> attributes. Any user with edit_faq...