PT-2025-53729 · Phpmyfaq · Phpmyfaq

Eclipse07077-Ljw

·

Published

2025-12-29

·

Updated

2026-01-07

·

CVE-2025-68951

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions phpMyFAQ versions 4.0.14 through 4.0.15
Description phpMyFAQ is a web application for creating FAQs. Versions 4.0.14 and 4.0.15 contain a stored cross-site scripting (XSS) issue. An attacker can inject and execute arbitrary JavaScript code in an administrator’s browser. This is achieved by registering a user with a display name containing HTML entities. When an administrator views the admin user list, the payload is decoded and rendered without proper escaping, leading to script execution within the administrator's context.
Recommendations Upgrade to phpMyFAQ version 4.0.16 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-68951
GHSA-JV8R-HV7Q-P6VC

Affected Products

Phpmyfaq