What is CVE-2026-76210?
CVE-2026-76210 is a path traversal vulnerability in phpMyFAQ versions before 4.1.6 where HTML in FAQ answers is not properly sanitized when generating PDFs. This allows an attacker with content editing permissions to read local files under the web root's content/ directory via an `<img>` tag's src attribute. Users should immediately upgrade to phpMyFAQ 4.1.6 or later.
Azərbaycanca: CVE-2026-76210 phpMyFAQ platformasının 4.1.6 versiyasından əvvəlki versiyalarında aşkarlanmış path traversal zəifliyidir. Bu zəiflik imtiyazlı istifadəçilərə FAQ cavablarındakı HTML-i sanitizasiya edilmədən PDF-ə çevirərkən local faylları `<img>` teqi vasitəsilə oxumağa imkan verir. İstifadəçilər dərhal phpMyFAQ 4.1.6 və ya daha yeni versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What privileges must an attacker have to exploit CVE-2026-76210?
To exploit this path traversal vulnerability, an attacker must have content editing permissions to modify FAQ answers in the phpMyFAQ platform.
What action should be taken to remediate CVE-2026-76210?
Users should immediately upgrade to phpMyFAQ version 4.1.6 or later to fix this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.