Vulnerabilities
Last updated 48 minutes ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
phpMyFAQ's two-factor authentication login bypasses the password factor | High Risk 8.1 | 3 days ago | 3 days ago |
|
|
phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Frontend FAQ Submission | High Risk 8.2 | 3 days ago | 3 days ago |
|
|
phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion | High Risk 8.0 | 3 days ago | 3 days ago |
|
|
phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration | Medium Risk 5.4 | 1 month ago | 3 days ago |
|
|
phpMyFAQ: IDOR Account Takeover | High Risk 8.8 | 4 months ago | 18 days ago |
|
|
phpMyFAQ: Ordinary Authenticated User Can Access Admin-Only API Endpoints Due to Insufficient Authorization Check in phpMyFAQ | Medium Risk 4.3 | 4 months ago | 18 days ago |
|
|
phpMyFAQ has SQL Injection in CurrentUser::setTokenData through unescaped OAuth token fields | High Risk 7.5 | 4 months ago | 18 days ago |
|
|
phpMyFAQ has stored XSS via Utils::parseUrl() in comment rendering | High Risk 7.6 | 4 months ago | 18 days ago |
|
|
phpMyFAQ: Unauthenticated Password Reset Endpoint Allows User Enumeration and Forced Password Change Without Token Validation | High Risk 8.2 | 4 months ago | 18 days ago |
|
|
phpMyFAQ has Stored XSS in FAQ Question/Answer via Encode-Decode Bypass of removeAttributes() Sanitization | Medium Risk 5.4 | 4 months ago | 18 days ago |
|
|
phpMyFAQ: Path Traversal in Client::deleteClientFolder enables arbitrary directory deletion by non-super-admin admins | Medium Risk 6.5 | 4 months ago | 18 days ago |
|
|
phpMyFAQ: Default Empty API Token Authentication Bypass | High Risk 7.5 | 4 months ago | 18 days ago |
|
|
phpMyFAQ has an Authorization Bypass in All Admin Pages Due to Non-Terminating Permission Check | Medium Risk 6.5 | 4 months ago | 18 days ago |
|
|
phpMyFAQ has an incomplete fix for GHSA-xvp4-phqj-cjr3 — editUser() and updateUserRights() lack authorization guards | High Risk 8.1 | 3 months ago | 18 days ago |
|
|
phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing | Low Risk 3.0 | 3 months ago | 18 days ago |
|
|
phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix) | Medium Risk 6.5 | 3 months ago | 18 days ago |
|
|
phpMyFAQ has stored XSS via | raw Filter in search.twig — html_entity_decode(strip_tags()) Bypass in Search Result Rendering | Medium Risk 6.9 | 4 months ago | 18 days ago |
|
|
phpMyFAQ's Missing CONFIGURATION_EDIT Permission Check on 12 Admin API Configuration Tab Endpoints Allows Information Disclosure by Any Authenticated User | Medium Risk 4.3 | 4 months ago | 18 days ago |
|
|
phpMyFAQ: Missing Password Reset Token Allows Account Takeover via Username/Email Enumeration | High Risk 8.2 | 4 months ago | 18 days ago |
|
|
phpMyFAQ has a SVG Sanitizer Entity Decoding Depth Limit Bypass Leading to Stored XSS | Medium Risk 5.4 | 4 months ago | 18 days ago |
|
|
phpMyFAQ has unauthenticated FAQ permission bypass via getFaqBySolutionId fallback query | High Risk 7.5 | 4 months ago | 18 days ago |
|
|
phpMyFAQ enables unauthenticated 2FA brute-force attack via /admin/check acceptance of arbitrary user-id | Critical 9.1 | 4 months ago | 18 days ago |
|
|
phpMyFAQ has unauthenticated SQL injection via User-Agent header in BuiltinCaptcha | Critical 9.8 | 4 months ago | 18 days ago |
|
|
phpMyFAQ duplicate email registration allows multiple accounts with the same email | High Risk 8.1 | 12 months ago | 18 days ago |
|
|
thorsten/phpmyfaq Unintended File Download Triggered by Embedded Frames | Medium Risk 4.9 | 1 year ago | 18 days ago |
|
|
phpMyFAQ vulnerable to Cross-site Scripting | High Risk 8.4 | 3 years ago | 18 days ago |
|
|
phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold | High Risk 8.8 | 1 month ago | 1 month ago |
|
|
phpMyFAQ has Potential Authenticated Path Traversal in PDF Export | Medium Risk 4.9 | 1 month ago | 1 month ago |
|
|
phpMyFAQ public FAQ APIs expose inactive FAQ content | Medium Risk 5.3 | 1 month ago | 1 month ago |
|
|
phpMyFAQ's Missing Authorization on Tag Deletion Allows Any Authenticated User to Delete Tags | Medium Risk 5.4 | 4 months ago | 2 months ago |
|
|
phpMyFAQ has a LIKE Wildcard Injection in Search.php — Unescaped % and _ Metacharacters Enable Broad Content Disclosure | Medium Risk 5.3 | 5 months ago | 5 months ago |
|
|
phpMyFAQ is Vulnerable to Stored XSS via Unsanitized Email Field in Admin FAQ Editor | Medium Risk 6.0 | 6 months ago | 5 months ago |
|
|
phpMyFAQ: SVG Sanitizer Bypass via HTML Entity Encoding Leads to Stored XSS and Privilege Escalation | Medium Risk 5.4 | 5 months ago | 5 months ago |
|
|
phpMyFAQ Allows Unauthenticated Account Creation via WebAuthn Prepare Endpoint | High Risk 7.5 | 7 months ago | 7 months ago |
|
|
phpMyFAQ vulnerable to Cross-site Scripting | Medium Risk 6.1 | 3 years ago | 7 months ago |
|
|
phpMyFAQ vulnerable to reflected Cross-site Scripting | Medium Risk 6.1 | 3 years ago | 7 months ago |
|
|
phpMyFAQ has Stored XSS in user list via admin-managed display_name | Medium Risk 5.4 | 9 months ago | 7 months ago |
|
|
phpMyFAQ contains a CSV injection vulnerability | High Risk 8.8 | 9 months ago | 7 months ago |
|
|
phpMyFAQ: /api/setup/backup accessible to any authenticated user (authz missing) | Medium Risk 6.5 | 8 months ago | 7 months ago |
|
|
phpMyFAQ: Attachment download allowed without dlattachment right (broken access control) | Medium Risk 6.5 | 8 months ago | 7 months ago |
|
|
phpMyFAQ: Public API endpoints expose emails and invisible questions | Medium Risk 5.3 | 8 months ago | 7 months ago |
|
|
phpMyFAQ has unauthenticated config backup download via /api/setup/backup | High Risk 7.5 | 9 months ago | 9 months ago |
|
|
phpMyFAQ has Authenticated SQL Injection in Configuration Update Functionality | High Risk 7.2 | 10 months ago | 10 months ago |
|
|
phpMyFAQ Vulnerable to Stored HTML Injection at FAQ | Medium Risk 5.2 | 1 year ago | 1 year ago |
|
|
Code Injection in thorsten/phpmyfaq | Critical 9.8 | 3 years ago | 1 year ago |
|
|
Cross-site Scripting in thorsten/phpmyfaq | Medium Risk 5.4 | 3 years ago | 1 year ago |
|
|
Command Injection in thorsten/phpmyfaq | Critical 9.8 | 3 years ago | 1 year ago |
|
|
Cross-site Scripting in thorsten/phpmyfaq | Medium Risk 5.4 | 3 years ago | 1 year ago |
|
|
phpMyFAQ Improper Access Control vulnerability | Medium Risk 6.6 | 3 years ago | 1 year ago |
|
|
phpMyFAQ vulnerable to Stored Cross-site Scripting | Medium Risk 6.1 | 3 years ago | 1 year ago |
Page 1