Package impact

php Packagist / phpmyfaq/phpmyfaq

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2026-35671 high 8.8 8.8 1h ago phpMyFAQ: IDOR Account Takeover php
CVE-2026-35676 high 8.2 8.2 1h ago phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint that allows attackers to change account passwords without token validation. Att… php
CVE-2026-35675 high 8.2 8.2 1h ago phpMyFAQ: Missing Password Reset Token Allows Account Takeover via Username/Email Enumeration php
CVE-2026-46367 high 7.6 7.6 13d ago phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in Utils::parseUrl() that allows authenticated users to inject JavaScript via malformed URLs in comments. Attackers can craf… php
CVE-2026-35672 high 7.5 7.5 1h ago phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in API v4.0 where the default empty api.apiClientToken allows unauthenticated users to create and modify FAQ entries. Attackers c… php
CVE-2026-45008 medium 6.5 6.5 13d ago phpMyFAQ before 4.1.2 contains a path traversal vulnerability in Client::deleteClientFolder that allows admins with INSTANCE_DELETE permission to delete arbitrary directories. Attackers can submit tr… php
CVE-2026-46360 medium 5.4 5.4 13d ago phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in SvgSanitizer::decodeAllEntities() that limits recursive entity decoding to 5 iterations, allowing attackers to bypass san… php
CVE-2026-46363 medium 5.4 5.4 13d ago phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in FAQ creation and update endpoints that bypass sanitization through encode-decode cycles. The vulnerability allows authent… php
CVE-2026-46365 medium 5.4 5.4 13d ago phpMyFAQ before 4.1.2 contains a missing authorization vulnerability in the DELETE /admin/api/content/tags/{tagId} endpoint that allows any authenticated user to delete tags. Any logged-in user, incl… php
CVE-2026-45009 medium 4.3 4.3 13d ago phpMyFAQ before 4.1.2 contains an insufficient authorization vulnerability in admin-api routes that allows authenticated ordinary users to access administrative endpoints by only checking login statu… php