Phpmyfaq
This hub aggregates every CVE we track for Phpmyfaq, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
164
CVEs tracked
10
Critical
49
High
0
In CISA KEV
Severity distribution
MEDIUM102HIGH49CRITICAL10LOW3
Monthly trend
0
0
0
2
1
0
0
0
0
0
0
0
0
1
1
3
3
1
0
5
17
3
4
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Phpmyfaq.
- CVE-2026-66399phpMyFAQ before 4.1.6 Privilege Escalation via Group Membership6.5
- CVE-2026-57996phpMyFAQ - Privilege Escalation via Missing SuperAdmin Guard in user/add Endpoint8.8
- CVE-2026-57994phpMyFAQ - Information Disclosure of Inactive FAQ Content via Public API Endpoints5.3
- CVE-2026-57961phpMyFAQ - Authenticated Path Traversal in PDF Export via concatenatePaths Function2.7
- CVE-2026-57995phpMyFAQ - Privilege Escalation via Missing Self-Rights Constraint in GroupController::updatePermissions8.8
- CVE-2026-56396phpMyFAQ - Privilege Escalation via Missing Authorization in editUser() and updateUserRights()8.8
- CVE-2026-49205phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)6.5
- CVE-2026-35676phpMyFAQ - Unauthenticated Password Reset via User Password Update Endpoint8.2
- CVE-2026-35675phpMyFAQ - Authentication Bypass via Missing Password Reset Token in /api/user/password/update8.2
- CVE-2026-35672phpMyFAQ - Authentication Bypass via Empty API Token7.5
- CVE-2026-35671phpMyFAQ - Insecure Direct Object Reference in User Password API8.8
- CVE-2026-46367phpMyFAQ - Stored XSS via Utils::parseUrl() in Comment Rendering7.6
- CVE-2026-46366phpMyFAQ - Unauthenticated Information Disclosure via getIdFromSolutionId Permission Bypass7.5
- CVE-2026-46365phpMyFAQ - Missing Authorization in Tag Deletion Endpoint5.4
- CVE-2026-46363phpMyFAQ - Stored XSS in FAQ Question/Answer via Encode-Decode Bypass5.4
Product normalization is registry-driven with AI assist and human review. How it works