Phpmyfaq
Vendor:
First CVE: Dec 31, 2004 · Active for 21 years
146
Total CVEs
More Total CVEs than 99% of tracked products
9.1
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Phpmyfaq over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
Jul 15, 2026
9 days ago
CVE Severity & Scoring
Phpmyfaq146 CVEs
64%
25%
9%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network126 (86.3%)
Unknown20 (13.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low126 (86.3%)
High0 (0.0%)
Unknown20 (13.7%)
User Interaction
None49 (33.6%)
Unknown20 (13.7%)
Required77 (52.7%)
Privileges Required
Low51 (34.9%)
High21 (14.4%)
None54 (37.0%)
Unknown20 (13.7%)
Top CVEs
Signals from CVEs in this product scope (146 CVEs).
146 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4825HIGH Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2 | Dec 15, 2011 | 7.5 | 63 | NO | YES |
CVE-2022-3766MEDIUM Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8. | Oct 31, 2022 | 6.1 | 42 | NO | YES |
CVE-2014-6046HIGH Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyFAQ before 2.8.13 allow remote attackers to hijack the authentication of unspecified users for requests that (1) | Aug 28, 2018 | 8.8 | 39 | NO | YES |
CVE-2026-57995HIGH phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that allows GROUP_EDIT administrators to grant arbitrary rights to groups | Jun 30, 2026 | 8.8 | 38 | NO | NO |
CVE-2025-69200HIGH phpMyFAQ is an open source FAQ web application. In versions prior to 4.0.16, an unauthenticated remote attacker can trigger generation of a configuration backup ZIP via `POST /api/ | Dec 29, 2025 | 7.5 | 38 | NO | YES |
CVE-2017-15808HIGH In phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config.php. | Oct 23, 2017 | 8.8 | 38 | NO | YES |
CVE-2017-15730HIGH In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php. | Oct 22, 2017 | 8.8 | 37 | NO | YES |
CVE-2026-56396HIGH phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. | Jun 21, 2026 | 8.8 | 36 | NO | NO |
CVE-2017-15735HIGH In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary. | Oct 22, 2017 | 8.8 | 36 | NO | YES |
CVE-2017-15734HIGH In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php. | Oct 22, 2017 | 8.8 | 36 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (146 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.7% of CVEs· 96th percentile
Nuclei
4 CVEs
2.7% of CVEs· 96th percentile
ExploitDB
22 CVEs
15.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (146 CVEs).
Media Mentions
Signals from CVEs in this product scope (146 CVEs).
Top CNAs Publishing CVEs For Phpmyfaq
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.1.0 | 3 | 6.3 | 0.9% | 0 | 1 |
| 4.0.7 | 1 | 9.8 | 0.4% | 0 | 0 |
| 4.0.0 | 1 | 7.5 | 0.5% | 0 | 0 |
| 3.2.5 | 8 | 6.2 | 0.8% | 0 | 0 |
| 3.2.0 | 3 | 5.1 | 0.6% | 0 | 0 |
| 3.1.12 | 1 | 8.0 | 0.5% | 0 | 0 |
| 2.8.4 | 2 | 5.5 | 1.5% | 0 | 0 |
| 2.8.3 | 2 | 5.5 | 1.5% | 0 | 0 |
| 2.8.2 | 2 | 5.5 | 1.5% | 0 | 0 |
| 2.8.1 | 2 | 5.5 | 1.5% | 0 | 0 |
| 2.8.0 | 2 | 5.5 | 1.5% | 0 | 0 |
| 2.7.9 | 2 | 5.5 | 1.5% | 0 | 0 |
| 2.7.8 | 2 | 5.5 | 1.5% | 0 | 0 |
| 2.7.7 | 2 | 5.5 | 1.5% | 0 | 0 |
| 2.7.6 | 2 | 5.5 | 1.5% | 0 | 0 |
| 2.7.5 | 2 | 5.5 | 1.5% | 0 | 0 |
| 2.7.4 | 2 | 5.5 | 1.5% | 0 | 0 |
| 2.7.3 | 2 | 5.5 | 1.5% | 0 | 0 |
| 2.7.2 | 2 | 5.5 | 1.5% | 0 | 0 |
| 2.7.1 | 2 | 5.5 | 1.5% | 0 | 0 |