Stored Cross-Site Scripting Vulnerability in phpMyFAQ by phpMyFAQ
CVE-2026-46363

5.4MEDIUM

Key Information:

Vendor

Thorsten

Status
Vendor
CVE Published:
15 May 2026

What is CVE-2026-46363?

A stored cross-site scripting vulnerability exists in phpMyFAQ prior to version 4.1.2, specifically impacting the FAQ creation and update endpoints. This issue arises from improper sanitization, allowing authenticated users with FAQ_ADD permission to inject malicious scripts through the question or answer fields. These scripts execute in the browsers of any user who views the affected FAQ content, posing significant risks to user security and data integrity.

Affected Version(s)

phpmyfaq 0 < 4.1.2

phpmyfaq 4.1.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

offset
.