PT-2026-78386 · Phpmyfaq · Phpmyfaq

·

CVE-2026-75920

·

Published

2026-08-04

·

Updated

2026-09-01

CVSS v4.0

6.0

Medium

VectorAV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions phpMyFAQ versions prior to 4.1.6
Description The software writes content backup ZIP archives to the web-accessible document root at the endpoint 'content.zip', which exposes sensitive files such as database credentials. Unauthenticated attackers can use a race condition—a situation where the outcome depends on the sequence or timing of uncontrollable events—by sending concurrent requests to download the temporary ZIP file before it is deleted. Additionally, attackers can exploit Cross-Site Scripting (XSS)—a flaw allowing the injection of malicious scripts into trusted websites—in administrative contexts to trigger authenticated backups and retrieve the archive.
Recommendations Update phpMyFAQ to version 4.1.6 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12610
CVE-2026-75920
GHSA-8HMH-MRX6-PQVF

Affected Products

Phpmyfaq