PT-2026-41365 · Thorsten · Phpmyfaq

Offset

·

Published

2026-05-15

·

Updated

2026-05-15

·

CVE-2026-46363

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in FAQ creation and update endpoints that bypass sanitization through encode-decode cycles. The vulnerability allows authenticated attackers with FAQ ADD permission to inject malicious script tags via question or answer parameters, which execute in every visitor's browser when FAQ content is rendered with the raw Twig filter.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-46363

Affected Products

Phpmyfaq