Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-49205: CWE-862: Missing Authorization in thorsten phpMyFAQCVE-2026-49205 0 phpMyFAQ versions prior to 4.1.4 have a missing authorization vulnerability in several API endpoints related to category, FAQ, and question creation and update. These endpoints rely only on a shared API key token check rather than verifying individual user permissions, potentially allowing unauthorized write operations. This issue was fixed in version 4.1.4. Join the discussion | CVE Database V5 | 06/18/2026, 21:12:34 UTC Added: 06/18/2026, 22:06:01 UTC |
CVE-2026-48488: CWE-328: Use of Weak Hash in thorsten phpMyFAQCVE-2026-48488 0 phpMyFAQ versions prior to 4.1.4 use SHA-1, a cryptographically broken hash algorithm, for hashing attachment passwords. SHA-1 has been vulnerable to collision attacks since 2017. This weakness was addressed in version 4.1.4. Join the discussion | CVE Database V5 | 06/08/2026, 15:15:12 UTC Added: 06/08/2026, 15:49:01 UTC |
CVE-2026-35676: Weak Password Recovery Mechanism for Forgotten Password in thorsten phpMyFAQCVE-2026-35676 0 phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint that allows attackers to change account passwords without token validation. Attackers can enumerate valid username and email pairs and force immediate password changes by sending PUT requests to the /api/index.php/user/password/update endpoint, causing account disruption and invalidating legitimate user credentials. Join the discussion | CVE Database V5 | 05/28/2026, 14:13:15 UTC Added: 05/28/2026, 15:33:38 UTC |
CVE-2026-35675: Improper Restriction of Excessive Authentication Attempts in thorsten phpMyFAQCVE-2026-35675 0 phpMyFAQ versions before 4.1.3 have an authentication bypass vulnerability in the password reset functionality. This flaw allows unauthenticated attackers to reset any user's password without requiring token verification or email confirmation. Exploitation enables attackers to enumerate valid usernames, receive plaintext passwords via email, and fully compromise user accounts, including those with administrative privileges. Join the discussion | CVE Database V5 | 05/28/2026, 14:13:14 UTC Added: 05/28/2026, 15:33:38 UTC |
CVE-2026-35672: Initialization of a Resource with an Insecure Default in thorsten phpMyFAQCVE-2026-35672 0 phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in API v4.0 where the default empty api.apiClientToken allows unauthenticated users to create and modify FAQ entries. Attackers can send an empty x-pmf-token header to bypass token validation and inject malicious content via POST endpoints /api/v4.0/faq/create, /api/v4.0/category, and /api/v4.0/question. Join the discussion | CVE Database V5 | 05/28/2026, 14:13:13 UTC Added: 05/28/2026, 15:33:38 UTC |
CVE-2026-35671: Incorrect Privilege Assignment in thorsten phpMyFAQCVE-2026-35671 0 phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated administrators to change any user's password without authorization verification. An attacker with low-privilege admin credentials can escalate to SuperAdmin by modifying the userId parameter in the overwrite-password API request. Join the discussion | CVE Database V5 | 05/28/2026, 14:13:12 UTC Added: 05/28/2026, 15:33:38 UTC |
CVE-2026-46367: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in thorsten phpmyfaqCVE-2026-46367 0 phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in Utils::parseUrl() that allows authenticated users to inject JavaScript via malformed URLs in comments. Attackers can craft URLs with unescaped quotes to inject event handlers, stealing admin session cookies and achieving full application takeover when visitors view affected FAQ pages. Join the discussion | CVE Database V5 | 05/15/2026, 18:36:46 UTC Added: 05/15/2026, 19:06:44 UTC |
CVE-2026-46365: Missing Authorization in thorsten phpmyfaqCVE-2026-46365 0 phpMyFAQ before 4.1.2 contains a missing authorization vulnerability in the DELETE /admin/api/content/tags/{tagId} endpoint that allows any authenticated user to delete tags. Any logged-in user, including regular frontend users, can delete arbitrary tags by sending a DELETE request with a valid session cookie, resulting in permanent data loss and disruption of FAQ organization. Join the discussion | CVE Database V5 | 05/15/2026, 18:36:43 UTC Added: 05/15/2026, 19:06:44 UTC |
CVE-2026-46364: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in thorsten phpmyfaqCVE-2026-46364 0 phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector() and BuiltinCaptcha::saveCaptcha() methods that interpolate unsanitized User-Agent headers into DELETE and INSERT queries. Unauthenticated attackers can exploit the public GET /api/captcha endpoint by crafting malicious User-Agent headers to perform time-based blind SQL injection, extracting sensitive data including user credentials, admin tokens, and SMTP credentials from the database. Join the discussion | CVE Database V5 | 05/15/2026, 18:36:42 UTC Added: 05/15/2026, 19:06:44 UTC |
CVE-2026-46363: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in thorsten phpmyfaqCVE-2026-46363 0 phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in FAQ creation and update endpoints that bypass sanitization through encode-decode cycles. The vulnerability allows authenticated attackers with FAQ_ADD permission to inject malicious script tags via question or answer parameters, which execute in every visitor's browser when FAQ content is rendered with the raw Twig filter. Join the discussion | CVE Database V5 | 05/15/2026, 18:36:42 UTC Added: 05/15/2026, 19:06:44 UTC |
Showing 1 to 10 of 14 results