Information Disclosure in phpMyFAQ Prior to Version 4.1.6
CVE-2026-75920

6MEDIUM

Key Information:

Vendor

Thorsten

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-75920?

An information disclosure vulnerability exists in phpMyFAQ versions prior to 4.1.6, whereby sensitive data is exposed through backup ZIP archives stored in a publicly accessible web document root. This misconfiguration allows unauthenticated attackers to make simultaneous requests to download these temporary ZIP files (content.zip) before they are deleted. Furthermore, if an attacker exploits Cross-Site Scripting (XSS) vulnerabilities within admin contexts, they could trigger authenticated backups and access sensitive archives, posing a significant risk to database credentials and other confidential information.

Affected Version(s)

phpMyFAQ 0 < 4.1.6

phpMyFAQ 4.1.6

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kevinnivekkevin
.