Local File Disclosure in phpMyFAQ Affected by HTML Sanitization Flaw
CVE-2026-76210

7.1HIGH

Key Information:

Vendor

Thorsten

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-76210?

A severe vulnerability in phpMyFAQ prior to version 4.1.7 allows attackers with editing permissions to inject executable HTML content into FAQ answers. This content can include an tag that references local files within the web server's directory structure. When a PDF is generated using TCPDF, the application attempts to access these files. If the file is not a valid image, an uncaught exception is thrown, potentially exposing sensitive information, including database credentials, depending on the PHP error configuration. This exploit puts your data security at risk and calls for immediate attention to ensure proper sanitization of user input.

Affected Version(s)

phpMyFAQ 0 < 4.1.6

phpMyFAQ 4.1.6

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kevinnivekkevin
.