phpmyfaq
Web & CMS Pluginsoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting phpmyfaq.
- CVE-2026-57996phpMyFAQ - Privilege Escalation via Missing SuperAdmin Guard in user/add Endpoint8.8
- CVE-2026-57994phpMyFAQ - Information Disclosure of Inactive FAQ Content via Public API Endpoints5.3
- CVE-2026-57961phpMyFAQ - Authenticated Path Traversal in PDF Export via concatenatePaths Function2.7
- CVE-2026-57995phpMyFAQ - Privilege Escalation via Missing Self-Rights Constraint in GroupController::updatePermissions8.8
- CVE-2026-56396phpMyFAQ - Privilege Escalation via Missing Authorization in editUser() and updateUserRights()8.8
- CVE-2026-34974phpMyFAQ: SVG Sanitizer Bypass via HTML Entity Encoding leads to Stored XSS and Privilege Escalation5.4
- CVE-2026-34973phpMyFAQ has a LIKE Wildcard Injection in Search.php — Unescaped % and _ Metacharacters Enable Broad Content Disclosure5.3
- CVE-2026-34729phpMyFAQ: Stored XSS via Regex Bypass in Filter::removeAttributes()6.1
- CVE-2026-34728phpMyFAQ: Path Traversal - Arbitrary File Deletion in MediaBrowserController8.7
- CVE-2026-32629phpMyFAQ: Stored XSS via Unsanitized Email Field in Admin FAQ Editor6.1
- CVE-2026-27836phpMyFAQ Allows Unauthenticated Account Creation via WebAuthn Prepare Endpoint7.5
- CVE-2026-24422phpMyFAQ: Public API endpoints expose emails and invisible questions5.3
- CVE-2026-24420phpMyFAQ: Attachment download allowed without dlattachment right (broken access control)6.5
- CVE-2026-24421phpMyFAQ missing authorization exposes /api/setup/backup to any authenticated user6.5
- CVE-2025-69200phpMyFAQ has unauthenticated config backup download via /api/setup/backup7.5