Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/thorsten/phpmyfaq

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

phpMyFAQ versions prior to 4.1.7 contain a missing authorization vulnerability where parent FAQ visibility checks are not enforced before returning child resources such as comments and attachments. This allows unauthenticated attackers to access restricted comment text, commenter email addresses, and attachment filenames for FAQ entries they cannot directly access.

Join the discussion

phpMyFAQ versions before 4.1.7 have an authentication bypass vulnerability due to failure to persist the WebAuthn login challenge. This allows an attacker who captures a valid WebAuthn assertion to replay it indefinitely and authenticate as the user without interaction or hardware key.

Join the discussion

phpMyFAQ versions before 4.1.7, when using the native pgsql PHP extension for PostgreSQL, improperly handle wildcard escaping in SQL LIKE queries. This flaw allows unauthenticated attackers to submit wildcard characters in the public FAQ search form, causing broad pattern matches and expensive sequential scans that can lead to denial of service. The issue does not affect the PDO PostgreSQL backend and does not enable SQL injection or data exfiltration.

Join the discussion

phpMyFAQ versions before 4.1.7 have a missing authorization vulnerability in the admin API read endpoints related to LDAP, Elasticsearch, OpenSearch, and dashboard configuration. This flaw allows any authenticated user to access sensitive administrative data without proper permission checks. Exploitation can reveal LDAP server topology, bind account names, search bases, index statistics, and site analytics.

Join the discussion

phpMyFAQ versions before 4.1.6 have a vulnerability where HTML in FAQ answers is not properly sanitized before generating PDFs using TCPDF. An attacker with permission to create or edit FAQ content can embed an <img> tag referencing local files under the web root's content/ directory. When the PDF is generated, phpMyFAQ tries to read the referenced file, causing an error that results in an uncaught exception. This exception discloses part of the file's contents in the stack trace to any user triggering the PDF export. The disclosed content is truncated by default but can be configured to reveal entire files, including sensitive data like database credentials.

Join the discussion

phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass vulnerability in AuthLdap::create(). When LDAP authentication is enabled, after a successful LDAP bind the code calls User::setStatus('active') unconditionally, which overwrites the account_status column of a pre-existing local account from 'blocked' to 'active'. As a result, a user whose local phpMyFAQ account has been administratively blocked can restore their account and log in by authenticating via LDAP. The state transition is not logged, so administrators cannot detect that the block was overridden. Fixed in 4.1.7.

Join the discussion

phpMyFAQ versions prior to 4.1.7 have a vulnerability in the two-factor authentication process where remember-me tokens are issued before the second-factor verification completes. This allows attackers with valid credentials to bypass 2FA by replaying the remember-me cookie, gaining full authenticated access without completing the second-factor challenge.

Join the discussion

phpMyFAQ versions prior to 4.1.7 contain a vulnerability in the PDF export endpoint that allows unauthenticated attackers to access draft FAQ metadata. This occurs because the application fails to validate the active status of FAQs, enabling retrieval of titles, solution IDs, author names, and last-update timestamps for inactive or unpublished FAQs via sequential FAQ identifiers.

Join the discussion

phpMyFAQ versions before 4.1.7 have a SQL injection vulnerability in the glossary create and update endpoints. Authenticated users with glossary add or edit permissions can exploit this by crafting a payload with a dangling backslash that escapes the closing quote, allowing arbitrary SQL commands to be injected. This vulnerability can lead to unauthorized reading of sensitive database information.

Join the discussion

phpMyFAQ versions prior to 4.1.6 create backup ZIP archives in a web-accessible location named content.zip, exposing sensitive data such as database credentials. Unauthenticated attackers can exploit a race condition to download these temporary files before deletion. Additionally, cross-site scripting (XSS) vulnerabilities in admin contexts may allow attackers to trigger backups and retrieve the archive. This vulnerability has a medium severity rating with a CVSS 4.0 score of 6.0.

Join the discussion

Showing 1 to 10 of 40 results

Filters:Package: pkg:github/thorsten/phpmyfaq
Page 1 of 4
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses