thorsten/phpmyfaq
Packagist109 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting thorsten/phpmyfaqpage 3 of 3
- CVE-2026-46366HIGHCVSS 7.5EG 7.5✓ Fixed in 4.1.22026-05-15
vulnerable: 2.10.0-alpha ... 4.1.1 (170 versions)
phpMyFAQ before 4.1.2 contains an information disclosure vulnerability in the getIdFromSolutionId() method that lacks permission filtering, allowing unauthenticated attackers to enumerate restricted FAQ entries and read their titles via th…
- CVE-2026-46367HIGHCVSS 7.6EG 7.6✓ Fixed in 4.1.22026-05-15
vulnerable: 4.1.1
phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in Utils::parseUrl() that allows authenticated users to inject JavaScript via malformed URLs in comments. Attackers can craft URLs with unescaped quotes to inject e…
- CVE-2026-47132MEDIUMCVSS 5.4EG 5.4✓ Fixed in 4.2.0-alpha2026-08-12
vulnerable: 2.10.0-alpha ... 4.1.7 (176 versions)
phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration ### Summary An authenticated SQL LIKE wildcard injection vulnerability in phpMyFAQ’s chat user search allows any logged-in user to bypass…
- CVE-2026-48488LOWCVSS 2.7EG 2.7✓ Fixed in 4.1.42026-06-08
vulnerable: 2.10.0-alpha ... 4.1.3 (172 versions)
phpMyFAQ is an open source FAQ web application. Prior to version 4.1.4, attachment passwords are hashed using SHA-1, a cryptographically broken algorithm. SHA-1 has been vulnerable to collision attacks since 2017 (SHAttered). Version 4.1.4…
- CVE-2026-49205MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.1.42026-06-18
vulnerable: 2.10.0-alpha ... 4.1.3 (172 versions)
phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryController. CVE-2026-24421 addressed this in the BackupController by adding: $this->userHasPermission(PermissionType::BA…
- CVE-2026-56396HIGHCVSS 8.8EG 8.8✓ Fixed in 4.1.42026-06-21
vulnerable: 2.10.0-alpha ... 4.1.3 (172 versions)
phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin users with edit_user permission can set is_s…
- CVE-2026-57961LOWCVSS 2.7EG 2.7✓ Fixed in 4.1.52026-07-10
vulnerable: 4.0.0 ... 4.1.4 (46 versions)
phpMyFAQ before 4.1.5 contains a potential authenticated path traversal vulnerability in the concatenatePaths() function within src/phpMyFAQ/Export/Pdf/Wrapper.php. A user with FAQ editing privileges can store HTML containing crafted image…
- CVE-2026-57994MEDIUMCVSS 5.3EG 5.3✓ Fixed in 4.1.52026-07-10
vulnerable: 4.1.0, 4.1.1, 4.1.2, 4.1.3, 4.1.4
phpMyFAQ before 4.1.5 applies inconsistent active=yes and publication-date filtering across its public FAQ API endpoints, allowing unauthenticated attackers to retrieve inactive (draft or review-only) FAQ content. Specifically, GET /api/v3…
- CVE-2026-57995HIGHCVSS 8.8EG 8.8✓ Fixed in 4.1.52026-07-01
vulnerable: 2.10.0-alpha ... 4.1.4 (173 versions)
phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that allows GROUP_EDIT administrators to grant arbitrary rights to groups without verifying they hold those rights themselves. A dele…
Check whether thorsten/phpmyfaq is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for thorsten/phpmyfaq CVEs against the assets you own.
Start Free Scan →