Vulnerability GHSA-rw77-vq4g-x3hp

High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 days ago
September 24, 2026 at 07:30 PM UTC
phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion
2.8.0 - 2.8.29 and 2.9.0 - 2.9.13 and 3.0.0 - 3.0.12 and 3.1.0 - 3.1.18 and 3.2.0 - 3.2.10 and 4.0.0 - 4.0.19 and 4.1.0 - 4.1.5
2.8.0 - 2.8.29 and 2.9.0 - 2.9.13 and 3.0.0 - 3.0.12 and 3.1.0 - 3.1.18 and 3.2.0 - 3.2.10 and 4.0.0 - 4.0.19 and 4.1.0 - 4.1.5

Summary

phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion

Details

Summary

The StopWords::add() method in phpMyFAQ builds a SQL INSERT statement using sprintf() and inserts the user-supplied stop word value directly into the query string without calling the application's database escaping function on it. A sibling method, StopWords::update(), which modifies an existing stop word, correctly escapes the same kind of input. The omission is isolated to the add() (insert) code path.

An authenticated administrator who can reach the stop-word management feature can submit a crafted value as the "word" parameter that breaks out of the SQL string literal and injects arbitrary SQL, including statements to drop tables, exfiltrate data, or modify other rows in the database.

Proof of Concept

Precondition: Attacker has valid administrator credentials (or has otherwise obtained an authenticated administrator session, e.g. via a separate session-hijacking or CSRF vector).

Attack steps:

  1. Authenticate to the phpMyFAQ administration panel.

  2. Navigate to the Stop Words management feature.

  3. Submit a new stop word with the following value instead of a normal word:

    test', 'en'); DROP TABLE faqstopwords; --
    
  4. The resulting SQL statement sent to the database becomes (table/column names approximate, based on the traced sprintf template):

    INSERT INTO faqstopwords VALUES(1, 'en', 'test', 'en'); DROP TABLE faqstopwords; --')
    
  5. The injected DROP TABLE faqstopwords; statement executes as a second SQL statement (subject to the database driver/PDO configuration permitting multi-statement execution; even where multi-statement execution is disabled, the same injection point allows classic single-statement SQLi techniques such as UNION-based data extraction or boolean/time-based blind injection against other tables the database user can access).

Root Cause

The codebase's established pattern for this class (StopWords.php) is to escape all string values via $this->configuration->getDb()->escape($value) before placing them into a sprintf()-built SQL string. This pattern is correctly applied to:

  • $this->language in add()
  • $word in update()

It is not applied to $word in add(). This is a single-line omission, not a structural design flaw — the safe pattern already exists in the same file and the same class, just inconsistently applied across the two methods that handle the same input type.

Related Vulnerabilities

Other vulnerabilities affecting the same packages

High Risk
3 days ago
phpMyFAQ's two-factor authentication login bypasses the password factor
3.2.0 - 3.2.10 and 4.0.0 - 4.0.19 and 4.1.0 - 4.1.5 GHSA-8gpw-xvpf-hvx5
3.2.0 - 3.2.10 and 4.0.0 - 4.0.19 and 4.1.0 - 4.1.5 GHSA-8gpw-xvpf-hvx5
High Risk
3 days ago
phpMyFAQ's two-factor authentication login bypasses the password factor
3.2.0 - 3.2.10 and 4.0.0 - 4.0.19 and 4.1.0 - 4.1.5 GHSA-8gpw-xvpf-hvx5
3.2.0 - 3.2.10 and 4.0.0 - 4.0.19 and 4.1.0 - 4.1.5 GHSA-8gpw-xvpf-hvx5
High Risk
3 days ago
phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Frontend FAQ Submission
2.8.0 - 2.8.29 and 2.9.0 - 2.9.13 and 3.0.0 - 3.0.12 and 3.1.0 - 3.1.18 and 3.2.0 - 3.2.10 and 4.0.0 - 4.0.19 and 4.1.0 - 4.1.8 GHSA-pgwp-vc7q-cvj3
2.8.0 - 2.8.29 and 2.9.0 - 2.9.13 and 3.0.0 - 3.0.12 and 3.1.0 - 3.1.18 and 3.2.0 - 3.2.10 and 4.0.0 - 4.0.19 and 4.1.0 - 4.1.8 GHSA-pgwp-vc7q-cvj3
High Risk
3 days ago
phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Frontend FAQ Submission
2.8.0 - 2.8.29 and 2.9.0 - 2.9.13 and 3.0.0 - 3.0.12 and 3.1.0 - 3.1.18 and 3.2.0 - 3.2.10 and 4.0.0 - 4.0.19 and 4.1.0 - 4.1.8 GHSA-pgwp-vc7q-cvj3
2.8.0 - 2.8.29 and 2.9.0 - 2.9.13 and 3.0.0 - 3.0.12 and 3.1.0 - 3.1.18 and 3.2.0 - 3.2.10 and 4.0.0 - 4.0.19 and 4.1.0 - 4.1.8 GHSA-pgwp-vc7q-cvj3
High Risk
1 month ago
phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold
2.8.0 - 2.8.29 and 2.9.0 - 2.9.13 and 3.0.0 - 3.0.12 and 3.1.0 - 3.1.18 and 3.2.0 - 3.2.10 and 4.0.0 - 4.0.19 and 4.1.0 - 4.1.4 GHSA-pg62-f8g4-4wqh
2.8.0 - 2.8.29 and 2.9.0 - 2.9.13 and 3.0.0 - 3.0.12 and 3.1.0 - 3.1.18 and 3.2.0 - 3.2.10 and 4.0.0 - 4.0.19 and 4.1.0 - 4.1.4 GHSA-pg62-f8g4-4wqh
View all vulnerabilities for these packages

Timeline

Published
3 days ago
September 24, 2026 at 07:30 PM UTC
Fixed (4.1.6)
2 months ago
July 13, 2026 at 12:34 PM UTC
Fixed (4.1.6)
2 months ago
July 13, 2026 at 12:34 PM UTC
Last Modified
3 days ago
September 24, 2026 at 07:45 PM UTC