Vulnerability index

Browse CVEs

117 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Phpmyfaq MEDIUM 5.4
CVE-2026-34974

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the regex-based SVG sanitizer in phpMyFAQ (SvgSanitizer.php) can be bypassed …

Fix: 4.1.1+
Fix from $1,600 2026-04-02
Phpmyfaq MEDIUM 5.3
CVE-2026-34973

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the searchCustomPages() method in phpmyfaq/src/phpMyFAQ/Search.php uses real_…

No fix yet
Fix from $1,600 2026-04-02
Phpmyfaq HIGH 8.1
CVE-2026-34728

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the MediaBrowserController::index() method handles file deletion for the medi…

Fix: 4.1.1+
Fix from $1,950 2026-04-02
Phpmyfaq MEDIUM 6.1
CVE-2026-32629

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, an unauthenticated attacker can submit a guest FAQ with an email address that…

Fix: 4.1.1+
Fix from $1,600 2026-04-02
Phpmyfaq HIGH 7.5
CVE-2026-27836

phpMyFAQ is an open source FAQ web application. Prior to version 4.0.18, the WebAuthn prepare endpoint (`/api/webauthn/prepare`) creates new active u…

Fix: 4.0.18+
Fix from $1,950 2026-02-27
Phpmyfaq HIGH 7.5
CVE-2026-24422

phpMyFAQ is an open source FAQ web application. In versions 4.0.16 and below, multiple public API endpoints improperly expose sensitive user informat…

Fix: 4.0.17+
Fix from $1,950 2026-01-24
Phpmyfaq MEDIUM 6.5
CVE-2026-24420

phpMyFAQ is an open source FAQ web application. Versions 4.0.16 and below allow an authenticated user without the dlattachment permission to download…

Fix: 4.0.17+
Fix from $1,600 2026-01-24
Phpmyfaq MEDIUM 6.5
CVE-2026-24421

phpMyFAQ is an open source FAQ web application. Versions 4.0.16 and below have flawed authorization logic which exposes the /api/setup/backup endpoin…

Fix: 4.0.17+
Fix from $1,600 2026-01-24
Phpmyfaq HIGH 7.5
CVE-2025-69200

phpMyFAQ is an open source FAQ web application. In versions prior to 4.0.16, an unauthenticated remote attacker can trigger generation of a configura…

Fix: 4.0.16+
Fix from $1,950 2025-12-29
Phpmyfaq MEDIUM 6.1
CVE-2025-68951

phpMyFAQ is an open source FAQ web application. Versions 4.0.14 and 4.0.15 have a stored cross-site scripting (XSS) vulnerability that allows an atta…

Fix: 4.0.16+
Fix from $1,600 2025-12-29
Phpmyfaq HIGH 8.0
CVE-2023-53929

phpMyFAQ 3.1.12 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into their profile names. Attacke…

No fix yet
Fix from $1,950 2025-12-17
Phpmyfaq HIGH 7.2
CVE-2025-62519

phpMyFAQ is an open source FAQ web application. Prior to version 4.0.14, an authenticated SQL injection vulnerability in the main configuration updat…

Fix: 4.0.14+
Fix from $1,950 2025-11-17
Phpmyfaq CRITICAL 9.8
CVE-2025-59943

phpMyFAQ is an open source FAQ web application. Versions 4.0-nightly-2025-10-03 and below do not enforce uniqueness of email addresses during user re…

Patch available
Fix from $2,300 2025-10-03
Phpmyfaq HIGH 7.6
CVE-2024-56199

phpMyFAQ is an open source FAQ web application. Starting no later than version 3.2.10 and prior to version 4.0.2, an attacker can inject malicious HT…

Fix: 4.0.2+
Fix from $1,950 2025-01-02
Phpmyfaq HIGH 7.2
CVE-2024-55889

phpMyFAQ is an open source FAQ web application. Prior to version 3.2.10, a vulnerability exists in the FAQ Record component where a privileged attack…

Fix: 3.2.10+
Fix from $1,950 2024-12-13
Phpmyfaq HIGH 7.5
CVE-2024-54141

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Prior to 4.0.0, phpMyFAQ exposes the database …

Patch available
Fix from $1,950 2024-12-06
Phpmyfaq HIGH 8.8
CVE-2024-28107

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. A SQL injection vulnerability has been discov…

Patch available
Fix from $1,950 2024-03-25
Phpmyfaq HIGH 7.2
CVE-2024-28105

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The category image upload function in phpmyfaq…

Patch available
Fix from $1,950 2024-03-25
Phpmyfaq MEDIUM 6.1
CVE-2024-28108

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Due to insufficient validation on the `content…

Patch available
Fix from $1,600 2024-03-25
Phpmyfaq MEDIUM 5.4
CVE-2024-28106

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. By manipulating the news parameter in a POST r…

Patch available
Fix from $1,600 2024-03-25
Phpmyfaq HIGH 8.8
CVE-2024-27299

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. A SQL injection vulnerability has been discove…

Patch available
Fix from $1,950 2024-03-25
Phpmyfaq MEDIUM 5.4
CVE-2024-27300

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The `email` field in phpMyFAQ's user control p…

Patch available
Fix from $1,600 2024-03-25
Phpmyfaq MEDIUM 6.1
CVE-2024-24574

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Unsafe echo of filename in phpMyFAQ\phpmyfaq\a…

Fix: 3.2.5+
Fix from $1,600 2024-02-05
Phpmyfaq MEDIUM 6.5
CVE-2024-22208

phpMyFAQ is an Open Source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The 'sharing FAQ' functionality allows any una…

Fix: 3.2.5+
Fix from $1,600 2024-02-05
Phpmyfaq MEDIUM 6.5
CVE-2024-22202

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. phpMyFAQ's user removal page allows an attacke…

Fix: 3.2.5+
Fix from $1,600 2024-02-05
Phpmyfaq MEDIUM 5.4
CVE-2023-6889

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.17.

Fix: 3.1.17+
Fix from $1,600 2023-12-16
Phpmyfaq MEDIUM 5.4
CVE-2023-6890

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.17.

Fix: 3.1.17+
Fix from $1,600 2023-12-16
Phpmyfaq MEDIUM 5.4
CVE-2023-5867

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.2.

Fix: 3.2.2+
Fix from $1,600 2023-10-31
Phpmyfaq CRITICAL 9.8
CVE-2023-5865

Insufficient Session Expiration in GitHub repository thorsten/phpmyfaq prior to 3.2.2.

Fix: 3.2.2+
Fix from $2,300 2023-10-31
Phpmyfaq MEDIUM 6.1
CVE-2023-5863

Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.2.2.

Fix: 3.2.2+
Fix from $1,600 2023-10-31