PT-2026-85493 · Phpmyfaq · Phpmyfaq

·

CVE-2026-85593

·

Published

2026-08-20

·

Updated

2026-09-04

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions phpMyFAQ versions prior to 4.1.8
Description A stored cross-site scripting issue exists where the convertOldInternalLinks() function in FaqHelper calls html entity decode() on sanitized FAQ content. This process reverses the entity-encoding protection, allowing authenticated users with FAQ editing privileges to inject JavaScript payloads. These payloads execute in the browsers of all users who view the affected FAQ pages.
Recommendations Update to version 4.1.8 or later. As a temporary mitigation, restrict FAQ editing privileges to only highly trusted users.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14267
CVE-2026-85593
GHSA-X6QJ-5JHF-XGPM

Affected Products

Phpmyfaq