CVE-2026-46359 HIGH

CVE-2026-46359: phpMyFAQ - SQL Injection in CurrentUser::setTokenData via Unescaped OAuth Token Fields

Vendor Thorsten
Product phpmyfaq
Weakness CWE-89 · SQLi
Published May 15, 2026
Last update May 28, 2026

CVSS base score

7.5/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

Description

phpMyFAQ before 4.1.2 contains a sql injection vulnerability in CurrentUser::setTokenData that allows authenticated attackers to execute arbitrary SQL by injecting malicious OAuth token claims. Attackers with Azure AD accounts containing SQL metacharacters in display names or JWT claims can break out of string literals and execute arbitrary database queries.

Key dates

Disclosure timeline

May 15, 2026 CVE published
May 28, 2026 Record updated