Threat Advisory

phpMyFAQ SQL Injection Allows Arbitrary Database Manipulation

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

phpMyFAQ is affected by security vulnerabilities involving authenticated path traversal, unauthorized exposure of inactive FAQ content, stored XSS, two-factor authentication bypass, and SQL injection.

CVE-2026-56736 (CVSS 8.2 – High): Stored XSS allows unauthenticated or low-privileged users to inject JavaScript into submitted FAQs, which executes when an administrator reviews or edits the entry and can potentially lead to administrator account takeover.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

phpMyFAQ is affected by security vulnerabilities involving authenticated path traversal, unauthorized exposure of inactive FAQ content, stored XSS, two-factor authentication bypass, and SQL injection.

CVE-2026-56736 (CVSS 8.2 – High): Stored XSS allows unauthenticated or low-privileged users to inject JavaScript into submitted FAQs, which executes when an administrator reviews or edits the entry and can potentially lead to administrator account takeover.[emaillocker id="1283"]

CVE-2026-56737 (CVSS 8.1 – High): A two-factor authentication login bypass allows attackers to authenticate to 2FA-enabled accounts using only a valid TOTP code without first proving the account password, potentially enabling account takeover.

CVE-2026-56738 (CVSS 8.5 – High): SQL injection in the StopWords::add() method allows authenticated administrators to inject SQL statements through an unsanitized stop-word value, potentially exposing, modifying, or deleting database data.

RECOMMENDATION:

We recommend you to update phpmyfaq/phpmyfaq to version 4.1.6.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu