PT-2026-97827 · Phpmyfaq · Phpmyfaq
CVE-2026-56736
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
phpMyFAQ versions prior to 4.2.0-alpha
Description
A stored cross-site scripting (XSS) issue exists that allows unauthenticated users or low-privileged registered users to inject arbitrary JavaScript. The attack occurs when an administrator reviews or edits a user-submitted FAQ entry, leading to potential admin account takeover via session theft. The issue stems from the use of
html entity decode() which converts HTML entities into executable HTML after strip tags() has already processed the input. Furthermore, the admin template renders this content using the Twig |raw filter without output sanitization.Technical details include:
- API Endpoint:
/api/faq/createis used to submit the malicious payload. - Vulnerable Parameters: The
answerparameter is susceptible to injection. - Vulnerable Functions: The
html entity decode()function is used improperly inphpmyfaq/src/phpMyFAQ/Controller/Frontend/Api/FaqController.php.
Recommendations
Update phpMyFAQ to version 4.2.0-alpha.
As a temporary mitigation, set the
main.enableWysiwygEditorFrontend configuration to false to prevent the decoding of HTML entities in user submissions.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpmyfaq