phpMyFAQ 是一款开源的常见问题解答(FAQ)Web 应用程序。版本 3.2.0 至 4.1.5 在其公开的二次认证(2FA)验证流程中存在身份认证绕过漏洞:攻击者无需先使用账户密码进行身份认证,只需提交该账户的数值型用户 ID 和一个有效或暴力破解得到的六位数 TOTP 验证码,即可接管任何启用了二次认证的账户,包括管理员账户。版本 4.1.6 已通过将 TOTP 验证绑定到成功通过密码认证后建立的会话,并限制 TOTP 验证失败次数的方式修复了此漏洞。目前尚无官方临时解决方案;受影响的部署应升级至 4.1
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56738 | 8.5 HIGH | phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion |
| CVE-2026-56736 | 8.2 HIGH | phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Frontend FAQ Submiss |
| CVE-2026-47132 | 5.4 MEDIUM | phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumer |
No comments yet