phpMyFAQ
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 191 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from December 31, 2004 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion
phpMyFAQ's two-factor authentication login bypasses the password factor
phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Frontend FAQ Submission
phpMyFAQ before 4.1.8 Stored XSS via html_entity_decode
phpMyFAQ before 4.1.8 Authorization Bypass via question/create
phpMyFAQ before 4.1.8 Authentication Bypass via Two-Factor Disable
phpMyFAQ before 4.2.0-alpha.2 Missing Authorization via Dashboard API
phpMyFAQ before 4.1.8 TOTP Secret Exposure via Data Export
phpMyFAQ before 4.1.8 CAPTCHA Bypass via store parameter
phpMyFAQ before 4.1.7 Missing Authorization via child resources
Monitor phpMyFAQ in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.