CVE-2026-48488

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.4, attachment passwords are hashed using SHA-1, a cryptographically broken algorithm. SHA-1 has been vulnerable to collision attacks since 2017 (SHAttered). Version 4.1.4 fixes the issue.
CVSS

No CVSS.

Configurations

No configuration.

History

08 Jun 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-08 16:16

Updated : 2026-06-08 16:16


NVD link : CVE-2026-48488

Mitre link : CVE-2026-48488

CVE.ORG link : CVE-2026-48488


JSON object : View

Products Affected

No product.

CWE
CWE-328

Use of Weak Hash