Package impact

php COMPOSER / phpMyFAQ/phpMyFAQ

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2026-46367 high 7.6 7.6 13d ago phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in Utils::parseUrl() that allows authenticated users to inject JavaScript via malformed URLs in comments. Attackers can craf… php
CVE-2026-45008 medium 6.5 6.5 13d ago phpMyFAQ before 4.1.2 contains a path traversal vulnerability in Client::deleteClientFolder that allows admins with INSTANCE_DELETE permission to delete arbitrary directories. Attackers can submit tr… php
CVE-2026-46360 medium 5.4 5.4 13d ago phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in SvgSanitizer::decodeAllEntities() that limits recursive entity decoding to 5 iterations, allowing attackers to bypass san… php
CVE-2026-46363 medium 5.4 5.4 13d ago phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in FAQ creation and update endpoints that bypass sanitization through encode-decode cycles. The vulnerability allows authent… php
CVE-2026-46365 medium 5.4 5.4 13d ago phpMyFAQ before 4.1.2 contains a missing authorization vulnerability in the DELETE /admin/api/content/tags/{tagId} endpoint that allows any authenticated user to delete tags. Any logged-in user, incl… php
CVE-2026-45009 medium 4.3 4.3 13d ago phpMyFAQ before 4.1.2 contains an insufficient authorization vulnerability in admin-api routes that allows authenticated ordinary users to access administrative endpoints by only checking login statu… php