CVE-2026-46363 MEDIUM

CVE-2026-46363: phpMyFAQ - Stored XSS in FAQ Question/Answer via Encode-Decode Bypass

Vendor Thorsten
Product phpmyfaq
Weakness CWE-79 · XSS
Published May 15, 2026
Last update May 28, 2026

CVSS base score

5.4/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

What the vulnerability does

Description

phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in FAQ creation and update endpoints that bypass sanitization through encode-decode cycles. The vulnerability allows authenticated attackers with FAQ_ADD permission to inject malicious script tags via question or answer parameters, which execute in every visitor's browser when FAQ content is rendered with the raw Twig filter.

Key dates

Disclosure timeline

May 15, 2026 CVE published
May 28, 2026 Record updated