Product
medium
advisory
phpMyFAQ Unauthenticated Password Reset Vulnerability (CVE-2026-35676)
2 rules 1 TTP 1 CVEphpMyFAQ before 4.1.3 is vulnerable to an unauthenticated password reset, allowing attackers to change account passwords without token validation by sending crafted PUT requests to the /api/index.php/user/password/update endpoint.
phpMyFAQ
cve
vulnerability
password reset
unauthenticated
2r
1t
1c
high
advisory
phpMyFAQ SQL Injection Vulnerability in CurrentUser::setTokenData (CVE-2026-46359)
2 rules 1 TTP 1 CVEphpMyFAQ before version 4.1.2 contains a SQL injection vulnerability in CurrentUser::setTokenData, allowing authenticated attackers with crafted Azure AD accounts to execute arbitrary SQL queries by injecting malicious OAuth token claims.
phpMyFAQ
sql-injection
vulnerability
2r
1t
1c
critical
advisory
phpMyFAQ Unauthenticated SQL Injection via User-Agent Header
2 rules 1 TTPUnauthenticated SQL injection vulnerability exists in phpMyFAQ <= 4.1.1 due to improper handling of the User-Agent header in BuiltinCaptcha, allowing attackers to inject malicious SQL payloads and potentially gain complete control of the datastore.
phpMyFAQ
sql-injection
unauthenticated
web-application
2r
1t