📦

phpmyfaq

Vendor: phpmyfaq

Actively Exploited 0 CISA KEV List
PoC / Exploits 23 Code Available
Total RCEs 8 Remote Access
Total CVEs 668 Total Indexed
Avg. EPSS 1.36% Exploit Prob.
Latest CVE CVE-2026-34974 Apr 02

Security Vulnerability Index

Page 12 / 67
8.8 CVSS

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/news.php.

EPSS: 0.58%
8.8 CVSS

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.adminlog.php.

EPSS: 0.59%
8.8 CVSS
CVE-2017-15730
Exploit Found

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php.

EPSS: 2.48%
8.8 CVSS

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for adding a glossary.

EPSS: 0.59%
4.8 CVSS

In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via metaDescription or metaKeywords.

EPSS: 0.61%
5.4 CVSS
CVE-2017-15727
Exploit Found

In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment.

EPSS: 1.80%
6.1 CVSS
CVE-2017-14619
Exploit Found

Cross-site scripting (XSS) vulnerability in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the "Title of your FAQ" field in the Configuration Module.

EPSS: 2.17%
4.8 CVSS
CVE-2017-14618
Exploit Found

Cross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the Questions field in an "Add New FAQ" action.

EPSS: 2.43%
9.8 CVSS

phpMyFAQ before 2.9.8 does not properly mitigate brute-force attacks that try many passwords in attempted logins quickly.

EPSS: 1.05%
6.1 CVSS

inc/PMF/Faq.php in phpMyFAQ before 2.9.7 has XSS in the question field.

EPSS: 0.67%