Local File Disclosure in phpMyFAQ Affected by HTML Sanitization Flaw
CVE-2026-76210
7.1HIGH
What is CVE-2026-76210?
A severe vulnerability in phpMyFAQ prior to version 4.1.7 allows attackers with editing permissions to inject executable HTML content into FAQ answers. This content can include an tag that references local files within the web server's directory structure. When a PDF is generated using TCPDF, the application attempts to access these files. If the file is not a valid image, an uncaught exception is thrown, potentially exposing sensitive information, including database credentials, depending on the PHP error configuration. This exploit puts your data security at risk and calls for immediate attention to ensure proper sanitization of user input.
Affected Version(s)
phpMyFAQ 0 < 4.1.6
phpMyFAQ 4.1.6
