Missing Authorization Vulnerability in phpMyFAQ by phpMyFAQ Team
CVE-2026-46365
5.4MEDIUM
What is CVE-2026-46365?
A missing authorization vulnerability exists in the DELETE /admin/api/content/tags/{tagId} endpoint in phpMyFAQ versions prior to 4.1.2. This issue allows any authenticated user, including those with minimal permissions, to delete tags indiscriminately by sending a DELETE request along with a valid session cookie. This can lead to significant disruptions in the organization of FAQs and permanent data loss, affecting the integrity of the information managed within phpMyFAQ.
Affected Version(s)
phpmyfaq 0 < 4.1.2
phpmyfaq 4.1.2
