Skip to main content

CVE-2026-56736: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in thorsten phpMyFAQ

0
High
VulnerabilityCVE-2026-56736cvecve-2026-56736cwe-79
Published: 09/24/2026 (09/24/2026, 14:21:17 UTC)
Source: CVE Database V5
Vendor/Project: thorsten
Product: phpMyFAQ

Description

phpMyFAQ is an open source FAQ web application. A stored cross-site scripting (XSS) vulnerability in versions prior to 4.2.0-alpha allows any unauthenticated user (or low-privileged registered user) to inject arbitrary JavaScript that executes in an administrator's browser when they review or edit a user-submitted FAQ entry. This leads to admin account takeover via session theft. The vulnerability exists because `html_entity_decode()` converts HTML entities into executable HTML after `strip_tags()` has already passed them through, and the admin template renders the content with Twig's `|raw` filter without any output sanitization. Version 4.2.0-alpha fixes the issue.

CVSS v3.1

Score 8.2high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

Affected software

thorsten

phpMyFAQ

Affected versions
<4.2.0-alpha
GitHub Actionsmore threats →ai
thorsten/phpMyFAQ
pkg:github/thorsten/phpMyFAQ
Affected versions
<4.2.0-alpha

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/24/2026, 15:04:41 UTC

Technical Analysis

CVE-2026-56736 is a stored XSS vulnerability in phpMyFAQ before version 4.2.0-alpha. The vulnerability allows unauthenticated or low-privileged users to inject arbitrary JavaScript into FAQ entries. This JavaScript executes in the administrator's browser during review or editing, enabling session theft and admin account takeover. The root cause is the use of html_entity_decode() converting HTML entities into executable HTML after strip_tags() has processed the input, combined with rendering the content using Twig's |raw filter without output sanitization. The vulnerability is fixed in version 4.2.0-alpha.

Potential Impact

Successful exploitation allows attackers to execute arbitrary JavaScript in the context of an administrator's browser, leading to session theft and potential administrative account takeover. This compromises the confidentiality and integrity of the admin account and the application management.

Mitigation Recommendations

Upgrade phpMyFAQ to version 4.2.0-alpha or later, where this vulnerability is fixed. No other mitigation is indicated or required per the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-06-22T19:17:28.959Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6ab5386df7a7c54106707ebc

Added to database: 09/24/2026, 14:49:17 UTC

Last enriched: 09/24/2026, 15:04:41 UTC

Last updated: 09/25/2026, 02:48:25 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses