CVE 7.6 HIGH

phpMyFAQ – Stored XSS via Utils::parseUrl() in Comment Rendering_CVE-2026-46367

7.6 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N

Description

phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in Utils::parseUrl() that allows authenticated users to inject JavaScript via malformed URLs in comments. Attackers can craft URLs with unescaped quotes to inject event handlers, stealing admin session cookies and achieving full application takeover when visitors view affected FAQ pages.

Basic Information

ID CVE-2026-46367
Source VulnCheck
Published May 15, 2026 at 18:36

Affected Product

Vendor thorsten
Product phpmyfaq
Version 4.1.1
Affected Versions thorsten phpmyfaq 4.1.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.