phpMyFAQ is affected by security vulnerabilities involving authenticated path traversal, unauthorized exposure of inactive FAQ content, stored XSS, two-factor authentication bypass, and SQL injection.
CVE-2026-56736 (CVSS 8.2 – High): Stored XSS allows unauthenticated or low-privileged users to inject JavaScript into submitted FAQs, which executes when an administrator reviews or edits the entry and can potentially lead to administrator account takeover.[/subscribe_to_unlock_form]
phpMyFAQ is affected by security vulnerabilities involving authenticated path traversal, unauthorized exposure of inactive FAQ content, stored XSS, two-factor authentication bypass, and SQL injection.
CVE-2026-56736 (CVSS 8.2 – High): Stored XSS allows unauthenticated or low-privileged users to inject JavaScript into submitted FAQs, which executes when an administrator reviews or edits the entry and can potentially lead to administrator account takeover.[emaillocker id="1283"]
CVE-2026-56737 (CVSS 8.1 – High): A two-factor authentication login bypass allows attackers to authenticate to 2FA-enabled accounts using only a valid TOTP code without first proving the account password, potentially enabling account takeover.
CVE-2026-56738 (CVSS 8.5 – High): SQL injection in the StopWords::add() method allows authenticated administrators to inject SQL statements through an unsanitized stop-word value, potentially exposing, modifying, or deleting database data.
We recommend you to update phpmyfaq/phpmyfaq to version 4.1.6.
The following reports contain further technical details:
[/emaillocker]