Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-56738— phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion

Quick assessment

Affected
thorsten phpMyFAQ
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

phpMyFAQ 是一款开源的 FAQ 网络应用程序。在 4.1.6 版本之前的构建中, 方法使用 构建 SQL 语句,并将用户提供的停止词(stop word)值直接拼接到查询字符串中,而没有调用应用程序的数据库转义函数对其进行转义。其相邻方法 (用于修改现有停止词)则正确地对其同类输入进行了转义。该遗漏仅局限于 (插入)代码路径。能够访问停止词管理功能且经过身份认证的管理员,可以提交精心构造的值作为 “word” 参数,从而突破 SQL 字符串字面量,注入任意 SQL 语句,例如删除表、外泄数据或修改数据库中的

CVSS 8.5 · High EPSS 0.26% · P16

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
thorsten phpMyFAQ < 4.1.6 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-56738

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion
Source: CVE Program / CVE List V5
Vulnerability Description
phpMyFAQ is an open source FAQ web application. The `StopWords::add()` method inversions prior to 4.1.6 builds a SQL `INSERT` statement using `sprintf()` and inserts the user-supplied stop word value directly into the query string without calling the application's database escaping function on it. A sibling method, `StopWords::update()`, which modifies an existing stop word, correctly escapes the same kind of input. The omission is isolated to the `add()` (insert) code path. An authenticated administrator who can reach the stop-word management feature can submit a crafted value as the "word" parameter that breaks out of the SQL string literal and injects arbitrary SQL, including statements to drop tables, exfiltrate data, or modify other rows in the database. Version 4.1.6 fixes the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
thorsten phpMyFAQ < 4.1.6 -

II. Public POCs for CVE-2026-56738

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-56738

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-56738 (1)

Vendor Advisories for CVE-2026-56738 (1)

Same Patch Batch · thorsten · 2026-09-24 · 4 CVEs total

CVE-2026-56736 8.2 HIGH phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Frontend FAQ Submiss
CVE-2026-56737 8.1 HIGH phpMyFAQ's two-factor authentication login bypasses the password factor
CVE-2026-47132 5.4 MEDIUM phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumer

IV. Related Vulnerabilities

V. Comments for CVE-2026-56738

No comments yet


Leave a comment