PT-2026-57180 · Phpmyfaq · Phpmyfaq

·

CVE-2026-57994

·

Published

2026-07-10

·

Updated

2026-08-25

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions phpMyFAQ versions prior to 4.1.5
Description Inconsistent filtering of active=yes and publication-date across public API endpoints allows unauthenticated users to retrieve inactive FAQ content, such as drafts or items pending review. This occurs at the following endpoints:
  • '/api/v3.1/faq/{categoryId}/{faqId}' returns the inactive FAQ title and full answer.
  • '/api/v3.1/faqs/tags/{tagId}' and '/api/v4.0/faqs/tags/{tagId}' return the inactive FAQ title and an answer preview.
Recommendations Update to version 4.1.5 or later.

Exploit

Fix

Information Disclosure

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57994
GHSA-MF8R-WM2W-F8C5

Affected Products

Phpmyfaq