📦

phpmyfaq

Vendor: phpmyfaq

Actively Exploited 0 CISA KEV List
PoC / Exploits 23 Code Available
Total RCEs 8 Remote Access
Total CVEs 668 Total Indexed
Avg. EPSS 1.36% Exploit Prob.
Latest CVE CVE-2026-34974 Apr 02

Security Vulnerability Index

Page 10 / 67
7.5 CVSS

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.1.9.

EPSS: 0.42%
5.4 CVSS

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.9.

EPSS: 0.48%
6.1 CVSS
CVE-2022-4407
Exploit Found

Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.9.

EPSS: 4.38%
6.1 CVSS
CVE-2022-3766
Exploit Found

Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

EPSS: 5.74%
5.4 CVSS

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

EPSS: 0.53%
9.8 CVSS

Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

EPSS: 1.17%
8.4 CVSS

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.0-alpha.

EPSS: 0.94%
7.2 CVSS

The admin backend in phpMyFAQ before 2.9.11 allows CSV injection in reports.

EPSS: 1.37%
8.8 CVSS

phpMyFAQ before 2.9.11 allows CSRF.

EPSS: 0.50%
5.3 CVSS
CVE-2014-6050
Exploit Found

phpMyFAQ before 2.8.13 allows remote attackers to bypass the CAPTCHA protection mechanism by replaying the request.

EPSS: 4.55%