PT-2026-41369 · Phpmyfaq · Phpmyfaq

·

CVE-2026-46367

·

Published

2026-05-06

·

Updated

2026-05-15

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions phpMyFAQ versions prior to 4.1.2
Description A stored cross-site scripting issue exists in the parseUrl() function of the Utils class. Authenticated users can inject JavaScript by submitting malformed URLs in comments. By using unescaped quotes to inject event handlers, attackers can steal administrator session cookies, potentially leading to a full application takeover when users view the affected FAQ pages.
Recommendations Update to version 4.1.2 or later. As a temporary workaround, restrict the ability of users to post URLs in comments until the update is applied.

Exploit

Fix

XSS

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46367
GHSA-9525-27VJ-C8R8
GHSA-W42G-JJ8W-FJ77

Affected Products

Phpmyfaq