Thorsten/phpmyfaq
103 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Thorsten/phpmyfaq, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
Thorsten/phpmyfaq CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 2 |
| 2025-01 | 1 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 1 |
| 2025-11 | 1 |
| 2025-12 | 3 |
| 2026-01 | 3 |
| 2026-02 | 1 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 17 |
| 2026-06 | 1 |
| 2026-07 | 0 |
| 2026-08 | 3 |
| 2026-09 | 0 |
Severity
How the 103 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical7
- High20
- Medium55
Latest CVEs
The 15 most recently published vulnerabilities affecting Thorsten/phpmyfaq.
- GHSA-pg62-f8g4-4wqhphpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold—
- GHSA-mf8r-wm2w-f8c5phpMyFAQ public FAQ APIs expose inactive FAQ content—
- GHSA-88g4-74f3-63x9phpMyFAQ has Potential Authenticated Path Traversal in PDF Export—
- GHSA-985r-q3qp-299hphpMyFAQ has an incomplete fix for GHSA-xvp4-phqj-cjr3 — editUser() and updateUserRights() lack authorization guards—
- GHSA-w9xh-5f39-vq89phpMyFAQ: Missing Password Reset Token Allows Account Takeover via Username/Email Enumeration—
- GHSA-gp95-j463-vv28phpMyFAQ: Default Empty API Token Authentication Bypass—
- GHSA-xvp4-phqj-cjr3phpMyFAQ: IDOR Account Takeover —
- GHSA-9qv9-8xv6-5p35phpMyFAQ: Unauthenticated Password Reset Endpoint Allows User Enumeration and Forced Password Change Without Token Validation—
- GHSA-289f-fq7w-6q2wphpMyFAQ has unauthenticated SQL injection via User-Agent header in BuiltinCaptcha—
- GHSA-gh9p-q46p-57g2phpMyFAQ: Path Traversal in Client::deleteClientFolder enables arbitrary directory deletion by non-super-admin admins—
- GHSA-99qv-g4x9-mgc3phpMyFAQ has unauthenticated FAQ permission bypass via getFaqBySolutionId fallback query—
- GHSA-pm8c-3qq3-72w7phpMyFAQ has SQL Injection in CurrentUser::setTokenData through unescaped OAuth token fields—
- GHSA-9pq7-mfwh-xx2jphpMyFAQ enables unauthenticated 2FA brute-force attack via /admin/check acceptance of arbitrary user-id—
- GHSA-jrc5-w569-h7h5phpMyFAQ: Ordinary Authenticated User Can Access Admin-Only API Endpoints Due to Insufficient Authorization Check in phpMyFAQ—
- GHSA-pqh6-8fxf-jx22phpMyFAQ has stored XSS via | raw Filter in search.twig — html_entity_decode(strip_tags()) Bypass in Search Result Rendering—
Product grouping is registry-driven, with AI assist and human review. How it works