Phpmyfaq · Phpmyfaq · CVE-2026-76215
**Name of the Vulnerable Software and Affected Versions**
phpMyFAQ versions prior to 4.1.7
**Description**
An issue exists where the software fails to apply visibility checks for parent FAQ records before returning associated child resources. Unauthenticated attackers can retrieve restricted comment text, commenter email addresses, and attachment filenames for FAQ records they are not authorized to access by querying the comments and attachments API endpoints.
**Recommendations**
Update to version 4.1.7 or later.