PatchSiren

thorsten CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM thorsten CVE published 2026-08-19

CVE-2026-76215

phpMyFAQ before version 4.1.7 fails to apply parent FAQ visibility checks before returning child resources, including comments and attachments. This allows unauthenticated attackers to retrieve restricted comment text, commenter email addresses, and attachment filenames by querying the comments and attachments API endpoints. The vulnerability has a MEDIUM CVSS score of 6.9, indicating a moderate level of [truncated]

CRITICAL thorsten CVE published 2026-08-19

CVE-2026-76214

phpMyFAQ before 4.1.7 has a critical vulnerability (CVE-2026-76214) that allows an attacker to replay a successful WebAuthn assertion indefinitely and authenticate as the user without interaction or hardware key. This is due to the failure to persist the WebAuthn login challenge generated by prepareForLogin. Organizations using phpMyFAQ for authentication, especially those relying on WebAuthn for secure a [truncated]

CRITICAL thorsten CVE published 2026-08-19

CVE-2026-76213

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T14:17:47.330Z and has not been modified since then. CVE-2026-76213 is a critical vulnerability in phpMyFAQ before version 4.1.7, allowing attackers with valid passwords to bypass the five-attempt limit for TOTP code guessing by obtaining a fresh session cookie and re-authenticating. This vulnerab [truncated]

MEDIUM thorsten CVE published 2026-08-19

CVE-2026-76212

The CVE-2026-76212 vulnerability affects phpMyFAQ installations using PostgreSQL via the native pgsql PHP extension. An incorrect LIKE ESCAPE character declaration allows unauthenticated attackers to submit malicious input, potentially causing denial of service attacks. System administrators and security teams should review and apply patches, verify input validation, and consider alternative backends. The [truncated]

MEDIUM thorsten CVE published 2026-08-19

CVE-2026-76211

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T14:17:46.653Z and has not been modified since then. phpMyFAQ before 4.1.7 fails to properly enforce CONFIGURATION_EDIT permission on admin API read endpoints for LDAP, Elasticsearch, OpenSearch, and dashboard configuration, allowing any authenticated user to access sensitive administrative data. [truncated]

HIGH thorsten CVE published 2026-08-19

CVE-2026-76210

CVE-2026-76210 is a vulnerability in phpMyFAQ before version 4.1.6 that allows for local file disclosure via PDF export. An attacker with permission to create or edit FAQ content can embed an <img> tag whose src references a local file under the web root's content/ directory. When the PDF is generated, phpMyFAQ attempts to read the referenced file; because it is not a valid image, the resulting error is c [truncated]

MEDIUM thorsten CVE published 2026-08-19

CVE-2026-76209

phpMyFAQ versions before v4.1.6 have a critical vulnerability in their API endpoints that allows attackers to bypass registration restrictions and create user accounts even when registration is disabled. This issue arises from the lack of validation of the security.enableRegistration setting in the API endpoints. The vulnerability was published on 2026-08-19T14:17:46.370Z and has not been modified since t [truncated]

HIGH thorsten CVE published 2026-08-19

CVE-2026-76208

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T14:17:46.220Z and has not been modified since then. CVE-2026-76208 is an authentication bypass vulnerability in phpMyFAQ versions 3.1.0 through 4.1.6. When LDAP authentication is enabled, after a successful LDAP bind the code calls User::setStatus('active') unconditionally, which overwrites the a [truncated]

HIGH thorsten CVE published 2026-08-19

CVE-2026-76207

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T14:17:46.073Z and has not been modified since then. CVE-2026-76207 is a high-severity vulnerability in phpMyFAQ before version 4.1.7, allowing attackers with valid credentials to bypass two-factor authentication by obtaining a remember-me cookie before 2FA verification completes. This enables the [truncated]

MEDIUM thorsten CVE published 2026-08-19

CVE-2026-76206

The CVE-2026-76206 vulnerability affects phpMyFAQ versions before 4.1.7, allowing unauthenticated attackers to retrieve draft FAQ metadata via the PDF export endpoint. This vulnerability is classified as an information disclosure issue. Organizations using affected versions should be aware of this vulnerability and take steps to mitigate it. The CVE record was published on 2026-08-19T14:17:45.930Z and has [truncated]

HIGH thorsten CVE published 2026-08-19

CVE-2026-76205

The CVE-2026-76205 vulnerability is a SQL injection issue in phpMyFAQ before version 4.1.7, specifically in the glossary create and update endpoints. This vulnerability allows authenticated users with glossary add or edit permissions to inject arbitrary SQL commands by crafting a payload with a dangling backslash. The vulnerability has a CVSS score of 8.6, indicating high severity. Organizations should pr [truncated]

MEDIUM thorsten CVE published 2026-08-19

CVE-2026-75920

CVE-2026-75920 is a vulnerability in phpMyFAQ prior to version 4.1.6. The issue allows unauthenticated attackers to access sensitive files, including database credentials, by exploiting the writing of content backup ZIP archives to the web-accessible document root at content.zip. This can be achieved by racing concurrent requests to download the temporary ZIP file before deletion or by exploiting XSS in a [truncated]

MEDIUM thorsten CVE published 2026-08-19

CVE-2026-75919

The CVE-2026-75919 authentication bypass vulnerability affects phpMyFAQ versions prior to 4.1.7. This vulnerability, located in the SetupController, allows unauthenticated attackers to execute database migrations and create configuration backups when maintenance mode is enabled. Attackers can exploit this by calling the POST /api/setup/update-database and POST /api/setup/backup endpoints, potentially lead [truncated]

HIGH thorsten CVE published 2026-08-19

CVE-2026-75918

The CVE-2026-75918 vulnerability affects phpMyFAQ, specifically versions before 4.1.7. The vulnerability class involves the storage of password reset tokens in a publicly accessible tracking file when user tracking is enabled. This allows unauthenticated attackers to read the tracking file, extract reset tokens, and replay them against the password reset API to gain unauthorized access to user accounts. T [truncated]

HIGH thorsten CVE published 2026-07-27

CVE-2026-66399

CVE-2026-66399 is a high-severity privilege escalation vulnerability in phpMyFAQ before version 4.1.6. The vulnerability exists in the GroupController::updateMembers() method, allowing administrators with only group-management permissions to join privileged groups without proper verification of required rights. This could enable attackers to add themselves to pre-existing groups with user-management right [truncated]

CRITICAL thorsten CVE published 2026-07-27

CVE-2026-66398

CVE-2026-66398 is a remote code execution vulnerability in phpMyFAQ before v4.1.6. The vulnerability exists in the configuration API and allows authenticated administrators with CONFIGURATION_EDIT and ATTACHMENT_ADD privileges to write arbitrary PHP files by manipulating the upgrade.lastDownloadedPackage setting. Attackers can exploit this by uploading a malicious ZIP file as an attachment, pointing the u [truncated]

HIGH thorsten CVE published 2026-07-27

CVE-2026-66397

CVE-2026-66397 is a high-severity path traversal vulnerability in phpMyFAQ before version 4.1.6. Authenticated attackers can exploit this vulnerability to delete arbitrary files, including the database.php configuration file, potentially allowing them to access the public setup wizard and create new superadmin accounts. This vulnerability exists in the Image::delete() method, where the existing_image fiel [truncated]

MEDIUM thorsten CVE published 2026-06-18

CVE-2026-49205

CVE-2026-49205 is a medium-severity vulnerability in phpMyFAQ's API CategoryController. Versions prior to 4.1.4 have missing authorization in the API, specifically in the CategoryController and other write endpoints. This allows unauthorized users to create, update, and delete FAQs and categories. The issue was addressed in version 4.1.4. Users should update to the latest version to prevent exploitation. [truncated]

LOW thorsten CVE published 2026-06-08

CVE-2026-48488

CVE-2026-48488 is a low-severity vulnerability in phpMyFAQ, a popular open-source FAQ web application. Prior to version 4.1.4, attachment passwords were hashed using SHA-1, a cryptographically broken algorithm that has been vulnerable to collision attacks since 2017 (SHAttered). This vulnerability has a CVSS score of 2.7 and was published on [cvePublishedAt]. The issue was fixed in version 4.1.4 of phpMyFAQ.

HIGH thorsten CVE published 2026-05-28

CVE-2026-35676

phpMyFAQ versions prior to 4.1.3 contain an unauthenticated password reset vulnerability in the user password update API endpoint. The vulnerability allows attackers to change account passwords without token validation by sending PUT requests to /api/index.php/user/password/update. Attackers can enumerate valid username and email pairs to force immediate password changes, resulting in account disruption a [truncated]

HIGH thorsten CVE published 2026-05-28

CVE-2026-35675

phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint. The flaw allows unauthenticated attackers to reset any user account password without token verification or email confirmation. Successful exploitation enables attackers to enumerate valid usernames, obtain plaintext passwords via email, and achieve complete account takeover including administrative access [truncated]

HIGH thorsten CVE published 2026-05-28

CVE-2026-35672

phpMyFAQ versions prior to 4.1.3 contain an authentication bypass vulnerability in API v4.0. The root cause is a default empty value for the `api.apiClientToken` configuration parameter, which allows unauthenticated attackers to bypass token validation by sending an empty `x-pmf-token` header. Successful exploitation permits creation and modification of FAQ entries via POST endpoints including `/api/v4.0/ [truncated]

HIGH thorsten CVE published 2026-05-28

CVE-2026-35671

phpMyFAQ before 4.1.3 contains an insecure direct object reference (IDOR) vulnerability in the admin API user password endpoint. Authenticated administrators with low privileges can change any user's password—including SuperAdmin accounts—by manipulating the userId parameter in overwrite-password API requests, enabling privilege escalation. The vulnerability was disclosed on 2026-05-28 with a CVSS 4.0 sco [truncated]

HIGH thorsten CVE published 2026-05-15

CVE-2026-46367

CVE-2026-46367 is a HIGH-severity stored cross-site scripting issue in phpMyFAQ before 4.1.2. The flaw is in Utils::parseUrl() and affects comment rendering, where malformed URLs can be turned into stored script content. Because the attacker must be authenticated but the payload is stored and later rendered to other users, the risk includes session theft and application takeover when affected FAQ pages are viewed.

HIGH thorsten CVE published 2026-05-15

CVE-2026-46366

CVE-2026-46366 describes an information disclosure issue in phpMyFAQ before 4.1.2. According to the supplied record, the getIdFromSolutionId() method does not apply permission filtering, which can let unauthenticated attackers enumerate solution IDs and reveal restricted FAQ entry titles through the /solution_id_{id}.html endpoint. The issue is confidentiality-focused, can affect restricted content, and i [truncated]

MEDIUM thorsten CVE published 2026-05-15

CVE-2026-46365

CVE-2026-46365 affects phpMyFAQ before 4.1.2 and is a missing-authorization issue in the DELETE /admin/api/content/tags/{tagId} endpoint. Any logged-in user, including non-admin frontend users, can delete tags with a valid session cookie, which can permanently disrupt FAQ organization and cause data loss.

CRITICAL thorsten CVE published 2026-05-15

CVE-2026-46364

CVE-2026-46364 is a critical unauthenticated SQL injection in phpMyFAQ before 4.1.2. The issue is triggered through the public /api/captcha flow, where malicious User-Agent values are interpolated into SQL in BuiltinCaptcha::garbageCollector() and BuiltinCaptcha::saveCaptcha(). Because the injection is reachable without authentication, exposed databases may leak sensitive information such as user credenti [truncated]

MEDIUM thorsten CVE published 2026-05-15

CVE-2026-46363

CVE-2026-46363 is a medium-severity stored cross-site scripting issue in phpMyFAQ before 4.1.2. Authenticated users with FAQ_ADD permission can inject malicious content through FAQ create/update paths, and the payload can persist until it is rendered to other users.

HIGH thorsten CVE published 2026-05-15

CVE-2026-46362

CVE-2026-46362 is a medium-severity authorization bypass affecting phpMyFAQ before 4.1.2. The issue is described as a failure in AbstractAdministrationController::userHasPermission() to stop execution after sending a forbidden response, which can let authenticated users reach permission-protected admin pages. The exposed data can include admin logs, user records, system information, and application config [truncated]

HIGH thorsten CVE published 2026-05-15

CVE-2026-46361

CVE-2026-46361 is a stored cross-site scripting vulnerability in phpMyFAQ before 4.1.2. The issue is described as unsafe rendering in search.twig, where result.question and result.answerPreview are output with the raw filter, bypassing Twig autoescape protections. An attacker with FAQ editor privileges can store HTML-entity-encoded payloads that survive the SearchController.php processing path and execute [truncated]