CVE Tools

Thorsten

101 CVEs tracked since 2022. Since Oct 2022, none of them reached CISA KEV.

Thorsten CVEs per month

Oct 2022 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Thorsten CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2022-1040
2022-11null or fewer
2022-12null or fewer
2023-0190
2023-02100
2023-03null or fewer
2023-04150
2023-0560
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-0950
2023-1050
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-0380
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-04null or fewer
2026-05170
2026-06null or fewer
2026-07null or fewer
2026-08140
2026-0980

Products

The products that kept showing up in Thorsten's monthly top three, with their CVEs summed over those months.

  1. Thorsten/phpmyfaq547 months
  2. Phpmyfaq474 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Thorsten.

  1. CVE-2026-47132phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration5.4
  2. CVE-2026-56738phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion—
  3. CVE-2026-56737phpMyFAQ's two-factor authentication login bypasses the password factor8.1
  4. CVE-2026-56736phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Frontend FAQ Submission8.2
  5. CVE-2026-85593phpMyFAQ before 4.1.8 Stored XSS via html_entity_decode5.4
  6. CVE-2026-85592phpMyFAQ before 4.1.8 Authorization Bypass via question/create3.7
  7. CVE-2026-85590phpMyFAQ before 4.1.8 Authentication Bypass via Two-Factor Disable—
  8. CVE-2026-85591phpMyFAQ before 4.1.8 Authentication Bypass via Unverified Password Change—
  9. CVE-2026-85589phpMyFAQ before 4.2.0-alpha.2 Missing Authorization via Dashboard API—
  10. CVE-2026-85588phpMyFAQ before 4.1.8 TOTP Secret Exposure via Data Export—
  11. CVE-2026-85587phpMyFAQ before 4.1.8 Incorrect Authorization via Admin Pages—
  12. CVE-2026-85586phpMyFAQ before 4.1.8 CAPTCHA Bypass via store parameter—
  13. CVE-2026-76215phpMyFAQ before 4.1.7 Missing Authorization via child resources5.3
  14. CVE-2026-76214phpMyFAQ before 4.1.7 WebAuthn Replay Attack via Challenge7.4
  15. CVE-2026-76213phpMyFAQ before 4.1.7 2FA Brute-Force via Session-Scoped Throttle7.4

The record

Peak rank
#52 in Apr 2023
Busiest month shown
May 2026, 17 CVEs
Months with a KEV entry
0 since Oct 2022
Monthly snapshots
11 since 2022
Thorsten's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store