PT-2026-78388 · Phpmyfaq · Phpmyfaq

·

CVE-2026-76206

·

Published

2026-08-19

·

Updated

2026-08-19

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions phpMyFAQ versions prior to 4.1.7
Description An issue exists where the software fails to validate the active status of an FAQ entry in the PDF export endpoint. This allows unauthenticated attackers to retrieve metadata from draft or unpublished FAQs by accessing the public PDF export route using sequential FAQ identifiers. The exposed information includes titles, solution IDs, author names, and last-update timestamps.
Recommendations Update to version 4.1.7 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76206
GHSA-F8PR-32PP-MP7H

Affected Products

Phpmyfaq