Phpmyfaq
This hub aggregates every CVE we track for Phpmyfaq, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
159
CVEs tracked
10
Critical
47
High
0
In CISA KEV
Severity distribution
MEDIUM100HIGH47CRITICAL10LOW2
Monthly trend
0
0
0
0
0
2
1
0
0
0
0
0
0
0
0
1
1
3
3
1
0
5
17
2
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Phpmyfaq.
- CVE-2026-56396phpMyFAQ - Privilege Escalation via Missing Authorization in editUser() and updateUserRights()8.8
- CVE-2026-49205phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)6.5
- CVE-2026-35676phpMyFAQ - Unauthenticated Password Reset via User Password Update Endpoint8.2
- CVE-2026-35675phpMyFAQ - Authentication Bypass via Missing Password Reset Token in /api/user/password/update8.2
- CVE-2026-35672phpMyFAQ - Authentication Bypass via Empty API Token7.5
- CVE-2026-35671phpMyFAQ - Insecure Direct Object Reference in User Password API8.8
- CVE-2026-46367phpMyFAQ - Stored XSS via Utils::parseUrl() in Comment Rendering7.6
- CVE-2026-46366phpMyFAQ - Unauthenticated Information Disclosure via getIdFromSolutionId Permission Bypass7.5
- CVE-2026-46365phpMyFAQ - Missing Authorization in Tag Deletion Endpoint5.4
- CVE-2026-46364phpMyFAQ - SQL Injection via User-Agent Header in BuiltinCaptcha9.8
- CVE-2026-46363phpMyFAQ - Stored XSS in FAQ Question/Answer via Encode-Decode Bypass5.4
- CVE-2026-46362phpMyFAQ - Authorization Bypass in Admin Pages via Non-Terminating Permission Check6.5
- CVE-2026-46361phpMyFAQ - Stored Cross-Site Scripting via raw Filter in search.twig6.9
- CVE-2026-46360phpMyFAQ - Stored XSS via Entity Decoding Depth Limit Bypass in SVG Sanitizer5.4
- CVE-2026-46359phpMyFAQ - SQL Injection in CurrentUser::setTokenData via Unescaped OAuth Token Fields7.5
Product normalization is registry-driven with AI assist and human review. How it works