CVE-2026-46363

phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in FAQ creation and update endpoints that bypass sanitization through encode-decode cycles. The vulnerability allows authenticated attackers with FAQ_ADD permission to inject malicious script tags via question or answer parameters, which execute in every visitor's browser when FAQ content is rendered with the raw Twig filter.
Configurations

No configuration.

History

15 May 2026, 21:16

Type Values Removed Values Added
References () https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-f5p7-2c9q-8896 - () https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-f5p7-2c9q-8896 -

15 May 2026, 19:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-15 19:17

Updated : 2026-05-28 16:16


NVD link : CVE-2026-46363

Mitre link : CVE-2026-46363

CVE.ORG link : CVE-2026-46363


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')