PT-2026-41362 · Thorsten · Phpmyfaq

Offset

·

Published

2026-05-15

·

Updated

2026-05-15

·

CVE-2026-46360

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in SvgSanitizer::decodeAllEntities() that limits recursive entity decoding to 5 iterations, allowing attackers to bypass sanitization. Authenticated users with FAQ EDIT permission can upload malicious SVG files with deeply nested ampersand encoding around numeric HTML entities to reconstruct javascript: URLs, which execute arbitrary JavaScript when clicked by other users viewing the uploaded SVG.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-46360

Affected Products

Phpmyfaq