phpMyFAQ vulnerabilities
3 CVEs tracked
phpMyFAQ appears in recent reports with multiple critical vulnerabilities. Key issues include authenticated path traversal via the 'existing_image' field leading to arbitrary file deletion (CVE-2026-66397), unauthenticated access to draft FAQ metadata through the PDF export endpoint (CVE-2026-76206), and a brute-force weakness in the two-factor authentication step due to a session-scoped failure counter (CVE-2026-76213). Defenders should focus on insufficient sanitization in `Image::delete()`, missing `active` status validation on the PDF export route, and the ability to bypass the five-attempt limit on 2FA by resetting the session-based counter. These flaws can lead to breaches of confidentiality, integrity, and availability.
Azərbaycanca: phpMyFAQ son hesabatlarda bir neçə kritik zəifliklə bağlı kontekstdə görünür. Əsas diqqət çəkən məqamlar autentifikasiyalı istifadəçilərin 'existing_image' sahəsindəki path traversal vasitəsilə fayl silməsi (CVE-2026-66397), autentifikasiyasız şəkildə draft FAQ məlumatlarının əldə olunması (CVE-2026-76206) və iki faktorlu autentifikasiya mərhələsində brute-force hücumu (CVE-2026-76213) imkanlarıdır. Müdafiəçilər CVE-2026-66397 üçün `Image::delete()` funksiyasında sanitizasiya nəzarətini, CVE-2026-76206 üçün PDF ixrac endpointində `active` status yoxlanışının olmamasını, CVE-2026-76213 üçün isə session əsaslı uğursuz cəhd sayğacının limiti keçmə riskini nəzərə almalıdır. Bu versiyalardakı istismar imkanları məxfiliyin, bütövlüyün və əlçatanlığın pozulmasına səbəb ola bilər.
This vendor's CVEs3
This hub is built from skopnix's own reporting on phpMyFAQ: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.