Phpmyfaq
This hub aggregates every CVE we track for Phpmyfaq, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
193
CVEs tracked
10
Critical
57
High
0
In CISA KEV
Severity distribution
MEDIUM112HIGH57CRITICAL10LOW4
Monthly trend
0
0
2
1
0
0
0
0
0
0
0
0
1
1
3
3
1
0
5
17
4
6
14
12
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Phpmyfaq.
- CVE-2026-47132phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration5.4
- CVE-2026-56738phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion
- CVE-2026-56737phpMyFAQ's two-factor authentication login bypasses the password factor8.1
- CVE-2026-56736phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Frontend FAQ Submission8.2
- CVE-2026-85593phpMyFAQ before 4.1.8 Stored XSS via html_entity_decode5.4
- CVE-2026-85592phpMyFAQ before 4.1.8 Authorization Bypass via question/create3.7
- CVE-2026-85590phpMyFAQ before 4.1.8 Authentication Bypass via Two-Factor Disable
- CVE-2026-85591phpMyFAQ before 4.1.8 Authentication Bypass via Unverified Password Change
- CVE-2026-85589phpMyFAQ before 4.2.0-alpha.2 Missing Authorization via Dashboard API
- CVE-2026-85588phpMyFAQ before 4.1.8 TOTP Secret Exposure via Data Export
- CVE-2026-85587phpMyFAQ before 4.1.8 Incorrect Authorization via Admin Pages
- CVE-2026-85586phpMyFAQ before 4.1.8 CAPTCHA Bypass via store parameter
- CVE-2026-76215phpMyFAQ before 4.1.7 Missing Authorization via child resources5.3
- CVE-2026-76214phpMyFAQ before 4.1.7 WebAuthn Replay Attack via Challenge7.4
- CVE-2026-76213phpMyFAQ before 4.1.7 2FA Brute-Force via Session-Scoped Throttle7.4
Product normalization is registry-driven with AI assist and human review. How it works