CVE Tools

Thorsten/phpmyfaq

103 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Thorsten/phpmyfaq, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Thorsten/phpmyfaq CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Thorsten/phpmyfaq CVEs per month
MonthCVEs
2024-100
2024-110
2024-122
2025-011
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-101
2025-111
2025-123
2026-013
2026-021
2026-030
2026-040
2026-0517
2026-061
2026-070
2026-083
2026-090

Severity

How the 103 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical79%
  • High2024%
  • Medium5567%

Latest CVEs

The 15 most recently published vulnerabilities affecting Thorsten/phpmyfaq.

  1. GHSA-pg62-f8g4-4wqhphpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold—
  2. GHSA-mf8r-wm2w-f8c5phpMyFAQ public FAQ APIs expose inactive FAQ content—
  3. GHSA-88g4-74f3-63x9phpMyFAQ has Potential Authenticated Path Traversal in PDF Export—
  4. GHSA-985r-q3qp-299hphpMyFAQ has an incomplete fix for GHSA-xvp4-phqj-cjr3 — editUser() and updateUserRights() lack authorization guards—
  5. GHSA-w9xh-5f39-vq89phpMyFAQ: Missing Password Reset Token Allows Account Takeover via Username/Email Enumeration—
  6. GHSA-gp95-j463-vv28phpMyFAQ: Default Empty API Token Authentication Bypass—
  7. GHSA-xvp4-phqj-cjr3phpMyFAQ: IDOR Account Takeover —
  8. GHSA-9qv9-8xv6-5p35phpMyFAQ: Unauthenticated Password Reset Endpoint Allows User Enumeration and Forced Password Change Without Token Validation—
  9. GHSA-289f-fq7w-6q2wphpMyFAQ has unauthenticated SQL injection via User-Agent header in BuiltinCaptcha—
  10. GHSA-gh9p-q46p-57g2phpMyFAQ: Path Traversal in Client::deleteClientFolder enables arbitrary directory deletion by non-super-admin admins—
  11. GHSA-99qv-g4x9-mgc3phpMyFAQ has unauthenticated FAQ permission bypass via getFaqBySolutionId fallback query—
  12. GHSA-pm8c-3qq3-72w7phpMyFAQ has SQL Injection in CurrentUser::setTokenData through unescaped OAuth token fields—
  13. GHSA-9pq7-mfwh-xx2jphpMyFAQ enables unauthenticated 2FA brute-force attack via /admin/check acceptance of arbitrary user-id—
  14. GHSA-jrc5-w569-h7h5phpMyFAQ: Ordinary Authenticated User Can Access Admin-Only API Endpoints Due to Insufficient Authorization Check in phpMyFAQ—
  15. GHSA-pqh6-8fxf-jx22phpMyFAQ has stored XSS via | raw Filter in search.twig — html_entity_decode(strip_tags()) Bypass in Search Result Rendering—

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store