Product:

Phpmyfaq

(Phpmyfaq)
Repositories https://github.com/thorsten/phpMyFAQ
#Vulnerabilities 124
Date Id Summary Products Score Patch Annotated
2024-02-05 CVE-2024-24574 phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Unsafe echo of filename in phpMyFAQ\phpmyfaq\admin\attachments.php leads to allowed execution of JavaScript code in client side (XSS). This vulnerability has been patched in version 3.2.5. Phpmyfaq 6.1
2009-11-20 CVE-2009-4040 Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.0.17 and 2.5.x before 2.5.2, when used with Internet Explorer 6 or 7, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the search page. Phpmyfaq N/A
2018-09-07 CVE-2018-16651 The admin backend in phpMyFAQ before 2.9.11 allows CSV injection in reports. Phpmyfaq 7.2
2017-07-12 CVE-2017-11187 phpMyFAQ before 2.9.8 does not properly mitigate brute-force attacks that try many passwords in attempted logins quickly. Phpmyfaq 9.8
2018-09-07 CVE-2018-16650 phpMyFAQ before 2.9.11 allows CSRF. Phpmyfaq 8.8
2017-04-07 CVE-2017-7579 inc/PMF/Faq.php in phpMyFAQ before 2.9.7 has XSS in the question field. Phpmyfaq 6.1
2017-10-23 CVE-2017-15809 In phpMyFaq before 2.9.9, there is XSS in admin/tags.main.php via a crafted tag. Phpmyfaq 6.1
2017-10-23 CVE-2017-15808 In phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config.php. Phpmyfaq 8.8
2017-10-22 CVE-2017-15735 In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary. Phpmyfaq 8.8
2017-10-22 CVE-2017-15734 In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php. Phpmyfaq 8.8