PT-2026-97827 · Phpmyfaq · Phpmyfaq

CVE-2026-56736

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions phpMyFAQ versions prior to 4.2.0-alpha
Description A stored cross-site scripting (XSS) issue exists that allows unauthenticated users or low-privileged registered users to inject arbitrary JavaScript. The attack occurs when an administrator reviews or edits a user-submitted FAQ entry, leading to potential admin account takeover via session theft. The issue stems from the use of html entity decode() which converts HTML entities into executable HTML after strip tags() has already processed the input. Furthermore, the admin template renders this content using the Twig |raw filter without output sanitization.
Technical details include:
  • API Endpoint: /api/faq/create is used to submit the malicious payload.
  • Vulnerable Parameters: The answer parameter is susceptible to injection.
  • Vulnerable Functions: The html entity decode() function is used improperly in phpmyfaq/src/phpMyFAQ/Controller/Frontend/Api/FaqController.php.
Recommendations Update phpMyFAQ to version 4.2.0-alpha. As a temporary mitigation, set the main.enableWysiwygEditorFrontend configuration to false to prevent the decoding of HTML entities in user submissions.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56736
GHSA-PGWP-VC7Q-CVJ3

Affected Products

Phpmyfaq