phpmyfaq/phpmyfaq Security Advisories for 3.0.0-beta.3 (9)
-
[MEDIUM] phpMyFAQ: Public API endpoints expose emails and invisible questions
PKSA-g4rh-637x-8kby CVE-2026-24422 GHSA-j4rc-96xj-gvqc
Affected version: <=4.0.16
Reported by:
GitHub -
[MEDIUM] phpMyFAQ: /api/setup/backup accessible to any authenticated user (authz missing)
PKSA-kw83-ss3b-tqsv CVE-2026-24421 GHSA-wm8h-26fv-mg7g
Affected version: <=4.0.16
Reported by:
GitHub -
[MEDIUM] phpMyFAQ: Attachment download allowed without dlattachment right (broken access control)
PKSA-bn6v-4n7v-4dtq CVE-2026-24420 GHSA-7p9h-m7m8-vhhv
Affected version: <=4.0.16
Reported by:
GitHub -
[MEDIUM] phpMyFAQ contains a CSV injection vulnerability
PKSA-1cq7-dh6p-78w8 CVE-2023-53929 GHSA-x2v3-9p22-w3x6
Affected version: <=3.1.12
Reported by:
GitHub -
[HIGH] phpMyFAQ has Authenticated SQL Injection in Configuration Update Functionality
PKSA-mvvf-b3jn-bt43 CVE-2025-62519 GHSA-fxm2-cmwj-qvx4
Affected version: <=4.0.13
Reported by:
GitHub -
[MEDIUM] phpMyFAQ vulnerable to stored XSS on attachments filename
PKSA-hdfq-3r6d-xzjt CVE-2024-24574 GHSA-7m8g-fprr-47fx
Affected version: <3.2.5
Reported by:
GitHub -
[MEDIUM] phpMyFAQ sharing FAQ functionality can easily be abused for phishing purposes
PKSA-qfjp-pm9r-s97r CVE-2024-22208 GHSA-9hhf-xmcw-r3xg
Affected version: <3.2.5
Reported by:
GitHub -
[MEDIUM] phpMyFAQ User Removal Page Allows Spoofing Of User Details
PKSA-q87w-7ynx-prc4 CVE-2024-22202 GHSA-6648-6g96-mg35
Affected version: <3.2.5
Reported by:
GitHub -
[HIGH] phpMyFAQ vulnerable to Cross-site Scripting
PKSA-k57y-tc6t-fmbw CVE-2022-3608 GHSA-6rj8-9cm9-6gff
Affected version: <=3.1.7
Reported by:
GitHub