LIVE · cybersecurity feed
Live wire
vendor

Phpmyfaq

6 CVEs published in the last four months. Exploited flaws first.

Critical0
High6
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-759188.8highphpmyfaqphpMyFAQ before 4.1.7 stores password reset tokens in a publicly accessible tracking file when user tracking is en17d ago
CVE-2026-762088.2highphpmyfaqphpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass vulnerability in AuthLdap::create().17d ago
CVE-2026-762058.1highphpmyfaqphpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the glossary create and update endpoints caused by17d ago
CVE-2026-762078.1highphpmyfaqphpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me tokens are issue17d ago
CVE-2026-762137.4highphpmyfaqphpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two-factor authentication step where the failure17d ago
CVE-2026-762147.4highphpmyfaqphpMyFAQ before 4.1.7 fails to persist the WebAuthn login challenge generated by prepareForLogin, because neither 17d ago

Filter the full tracker by Phpmyfaq