Browse all 6 CVE security advisories affecting Phpmyfaq. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-57996 | phpMyFAQ - Privilege Escalation via Missing SuperAdmin Guard in user/add Endpoint — phpMyFAQ CWE-269 | 8.8 | High | 2026-07-15 |
| CVE-2026-57994 | phpMyFAQ - Information Disclosure of Inactive FAQ Content via Public API Endpoints — phpMyFAQ CWE-200 | 5.3 | Medium | 2026-07-10 |
| CVE-2026-57961 | phpMyFAQ - Authenticated Path Traversal in PDF Export via concatenatePaths Function — phpMyFAQ CWE-22 | 2.7 | Low | 2026-07-10 |
| CVE-2026-57995 | phpMyFAQ - Privilege Escalation via Missing Self-Rights Constraint in GroupController::updatePermissions — phpMyFAQ CWE-269 | 8.8 | High | 2026-06-30 |
| CVE-2026-56396 | phpMyFAQ - Privilege Escalation via Missing Authorization in editUser() and updateUserRights() — phpMyFAQ CWE-862 | 8.8 | High | 2026-06-21 |
| CVE-2023-53929 | phpMyFAQ 3.1.12 CSV Injection via User Profile Export — phpMyFAQ CWE-1236 | 8.8 | High | 2025-12-17 |
This page lists every published CVE security advisory associated with Phpmyfaq. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.