CVE-2026-85593: phpMyFAQ before 4.1.8 Stored XSS via html_entity_decode

Published Sep 4, 2026
·
Updated

phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting vulnerability in FaqHelper::convertOldInternalLinks() that calls htmlentitydecode() on sanitized FAQ content, reversing entity-encoding protection. Authenticated users with FAQ editing privileges can inject JavaScript payloads that execute in the browsers of all users viewing the affected FAQ pages.

Affected Software

1 affected component
PhpMyFaq phpmyfaq<4.1.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade phpMyFAQ to a version that resolves this vulnerability.

    Fixed in 4.1.8
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch Stored XSS via html_entity_decode

Event History

Sep 4, 2026
CVE Published
via MITRE·11:29 AM
Data Sourced
via MITRE·11:29 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue and who is exposed to the injected script?

An authenticated user with FAQ editing privileges can inject the payload. The script can execute in the browsers of all users who view an affected FAQ page.

2

Which deployments are affected?

phpMyFAQ versions before 4.1.8 are affected. The issue is reached when FAQ content is processed by FaqHelper::convertOldInternalLinks().

3

What is the immediate mitigation if upgrading is not possible?

Restrict FAQ editing privileges to trusted users, because those privileges are required to inject the stored payload.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203