Phpmyfaq

Phpmyfaq

159 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.34%
  • Veröffentlicht 02.04.2026 14:47:22
  • Zuletzt bearbeitet 24.07.2026 21:10:00

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the searchCustomPages() method in phpmyfaq/src/phpMyFAQ/Search.php uses real_escape_string() (via escape()) to sanitize the search term before embedding it in LIKE clauses. Howev...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 02.04.2026 14:46:22
  • Zuletzt bearbeitet 07.04.2026 14:52:49

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, there is a stored XSS vulnerability via Regex Bypass in Filter::removeAttributes(). This issue has been patched in version 4.1.1.

Exploit
  • EPSS 0.69%
  • Veröffentlicht 02.04.2026 14:44:19
  • Zuletzt bearbeitet 07.04.2026 14:57:06

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the MediaBrowserController::index() method handles file deletion for the media browser. When the fileRemove action is triggered, the user-supplied name parameter is concatenated ...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 02.04.2026 14:43:14
  • Zuletzt bearbeitet 07.04.2026 16:10:02

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, an unauthenticated attacker can submit a guest FAQ with an email address that is syntactically valid per RFC 5321 (quoted local part) yet contains raw HTML — for example "<script...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 27.02.2026 19:54:51
  • Zuletzt bearbeitet 04.03.2026 16:08:53

phpMyFAQ is an open source FAQ web application. Prior to version 4.0.18, the WebAuthn prepare endpoint (`/api/webauthn/prepare`) creates new active user accounts without any authentication, CSRF protection, captcha, or configuration checks. This allo...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 24.01.2026 02:02:30
  • Zuletzt bearbeitet 28.01.2026 18:10:23

phpMyFAQ is an open source FAQ web application. In versions 4.0.16 and below, multiple public API endpoints improperly expose sensitive user information due to insufficient access controls. The OpenQuestionController::list() endpoint calls Question::...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 24.01.2026 01:57:28
  • Zuletzt bearbeitet 28.01.2026 18:25:46

phpMyFAQ is an open source FAQ web application. Versions 4.0.16 and below allow an authenticated user without the dlattachment permission to download FAQ attachments due to a incomprehensive permissions check. The presence of a right key is improperl...

Exploit
  • EPSS 1.76%
  • Veröffentlicht 24.01.2026 01:43:10
  • Zuletzt bearbeitet 30.01.2026 17:29:58

phpMyFAQ is an open source FAQ web application. Versions 4.0.16 and below have flawed authorization logic which exposes the /api/setup/backup endpoint to any authenticated user despite their permissions. SetupController.php uses userIsAuthenticated()...

Exploit
  • EPSS 2.05%
  • Veröffentlicht 29.12.2025 15:24:51
  • Zuletzt bearbeitet 07.10.2026 12:10:00

phpMyFAQ is an open source FAQ web application. In versions prior to 4.0.16, an unauthenticated remote attacker can trigger generation of a configuration backup ZIP via `POST /api/setup/backup` and then download the generated ZIP from a web-accessibl...

  • EPSS 0.24%
  • Veröffentlicht 29.12.2025 15:18:58
  • Zuletzt bearbeitet 07.10.2026 12:10:00

phpMyFAQ is an open source FAQ web application. Versions 4.0.14 and 4.0.15 have a stored cross-site scripting (XSS) vulnerability that allows an attacker to execute arbitrary JavaScript in an administrator’s browser by registering a user whose displa...