PT-2026-29423 · Phpmyfaq · Phpmyfaq

Wooseokdotkim

·

Published

2026-03-31

·

Updated

2026-04-02

·

CVE-2026-32629

CVSS v4.0

6.4

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions phpMyFAQ versions prior to 4.1.1
Description prior to version 4.1.1, an unauthenticated attacker can submit a guest FAQ with an email address containing raw HTML that is accepted as valid by PHP's FILTER VALIDATE EMAIL function. This email is stored in the database without sanitization and rendered in the admin FAQ editor template using Twig's |raw filter, bypassing auto-escaping. This allows for the execution of arbitrary scripts in the administrator's browser when reviewing the FAQ, potentially leading to session cookie theft and full admin account takeover.
Recommendations Update to version 4.1.1 or later.

Exploit

Fix

RCE

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-32629
GHSA-98GW-W575-H2PH

Affected Products

Phpmyfaq