pkg:Packagist/thorsten/phpmyfaq
共 89 筆 CVECRITICAL6HIGH29MEDIUM52
✅ 檢查你的版本
所有已知漏洞
- from 0, < 3.1.11
- from 0, < 3.1.11
- from 0, < 3.1.10
- from 0, < 3.1.8
- from 0, < 3.1.18
- from 0, < 3.1.18
- HIGH8.9CVE-2023-1758thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) in FAQ comment username parameterfrom 0, < 3.1.12
- from 0, < 4.1.3
- from 0, <= 3.1.12
- from 0, < 3.1.16
- HIGH8.8CVE-2023-4006phpMyFAQ Improper Neutralization of Formula Elements in a CSV File vulnerabilityfrom 0, < 3.1.16
- HIGH8.8CVE-2023-1762thorsten/phpmyfaq vulnerable privilege escalation from improper privilege managementfrom 0, < 3.1.12
- from 0, < 3.1.11
- from 0, < 3.1.11
- from 0, < 2.9.11
- HIGH8.6CVE-2024-54141phpMyFAQ Generates an Error Message Containing Sensitive Information if database server is not availablefrom 0, < 4.0.0
- from 0, < 3.2.0-alpha
- from 0, < 3.1.18
- from 0, < 3.1.12
- HIGH8.3CVE-2023-1880thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via artlang parameterfrom 0, < 3.1.12
- from 0, < 3.1.12
- HIGH8.2CVE-2026-35675phpMyFAQ: Missing Password Reset Token Allows Account Takeover via Username/Email Enumerationfrom 0, < 4.1.3
- HIGH8.2CVE-2026-35676phpMyFAQ: Unauthenticated Password Reset Endpoint Allows User Enumeration and Forced Password Change Without Token Validationfrom 0, < 4.1.3
- from 0, < 3.1.13
- HIGH8.1CVE-2025-59943phpMyFAQ duplicate email registration allows multiple accounts with the same email>= 4.0.7, < 4.0.13
- HIGH8.1CVE-2023-1882thorsten/phpmyfaq vulnerable to DOM cross-site scripting (XSS) via configuration privacy note URL parameterfrom 0, < 3.1.12
- HIGH8.1CVE-2023-1757thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via FAQ News link parameterfrom 0, < 3.1.12
- from 0, < 3.2.2
- from 0, < 4.1.3
- from 0, < 4.0.18
- from 0, < 4.0.16
- from 0, < 3.1.9
- from 0, < 3.2.1
- from 0, < 3.1.12
- from 0, < 4.0.14
- from 0, < 3.1.14
- from 0, < 3.1.13
- MEDIUM6.5CVE-2026-24421phpMyFAQ: /api/setup/backup accessible to any authenticated user (authz missing)from 0, < 4.0.17
- MEDIUM6.5CVE-2026-24420phpMyFAQ: Attachment download allowed without dlattachment right (broken access control)from 0, < 4.0.17
- from 0, < 3.1.18
- MEDIUM6.3CVE-2023-5866Sensitive cookie in HTTPS session without 'Secure' attribute in thorsten/phpmyfaqfrom 0, < 3.2.1
- from 0, < 3.1.18
- MEDIUM6.3CVE-2023-1885thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via category field name parameterfrom 0, < 3.1.12
- from 0, < 3.2.2
- from 0, < 3.1.13
- from 0, < 3.1.13
- from 0, < 3.1.10
- from 0, < 3.1.10
- from 0, < 3.1.9
- from 0, < 3.1.8
- from 0, < 3.1.14
- from 0, < 3.1.12
- MEDIUM5.4CVE-2026-34974phpMyFAQ: SVG Sanitizer Bypass via HTML Entity Encoding Leads to Stored XSS and Privilege Escalationfrom 0, < 4.1.1
- >= 4.0.14, < 4.0.16
- from 0, < 3.1.17
- from 0, < 3.1.17
- from 0, < 3.2.2
- from 0, < 3.2.0-beta
- from 0, < 3.2.0-beta
- from 0, < 3.1.12
- from 0, < 3.1.12
- from 0, < 3.1.12
- from 0, < 3.1.12
- from 0, < 3.1.11
- from 0, < 3.1.11
- from 0, < 3.1.11
- from 0, < 3.1.11
- from 0, < 3.1.10
- from 0, < 3.1.10
- from 0, < 3.1.10
- from 0, < 3.1.10
- from 0, < 3.1.10
- from 0, < 3.1.9
- from 0, < 3.1.8
- MEDIUM5.3CVE-2026-34973phpMyFAQ has a LIKE Wildcard Injection in Search.php — Unescaped % and _ Metacharacters Enable Broad Content Disclosurefrom 0, < 4.1.1
- from 0, < 4.0.17
- >= 3.2.10, <= 4.0.1
- from 0, < 3.2.0-beta.2
- from 0, < 3.2.10
- from 0, < 3.1.12
- from 0, < 3.1.12
- from 0, < 3.1.11
- MEDIUM4.7CVE-2023-1884thorsten/phpmyfaq vulnerable to cross-site scripting (XSS) via stopword parameterfrom 0, < 3.1.12
- MEDIUM4.7CVE-2023-1879thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via updatecategory parameterfrom 0, < 3.1.12
- MEDIUM4.7CVE-2023-1756thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via HTML exportfrom 0, < 3.1.12
- from 0, < 3.1.12
- from 0, < 3.1.11
- from 0, < 4.1.1
- from 0, < 3.1.10