Information Disclosure in phpMyFAQ Prior to Version 4.1.6
CVE-2026-75920
6MEDIUM
What is CVE-2026-75920?
An information disclosure vulnerability exists in phpMyFAQ versions prior to 4.1.6, whereby sensitive data is exposed through backup ZIP archives stored in a publicly accessible web document root. This misconfiguration allows unauthenticated attackers to make simultaneous requests to download these temporary ZIP files (content.zip) before they are deleted. Furthermore, if an attacker exploits Cross-Site Scripting (XSS) vulnerabilities within admin contexts, they could trigger authenticated backups and access sensitive archives, posing a significant risk to database credentials and other confidential information.
Affected Version(s)
phpMyFAQ 0 < 4.1.6
phpMyFAQ 4.1.6
