CVE-2024-29179: medium-severity vulnerability in thorsten phpMyFAQ
phpMyFAQ Stored Cross-site Scripting at File Attachments
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.3epss 0.5%
exploitation probability
0.5%top 58% of all CVEs
observed exploitation
nono source reports it
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. An attacker with admin privileges can upload an attachment containing JS code without extension and the application will render it as HTML which allows for XSS attacks.
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L
Affected products
thorsten · phpMyFAQRelated CVEs — thorsten phpMyFAQ
In the same product, most dangerous first.
CVE-2024-55889MEDIUMphpMyFAQ Vulnerable to Unintended File Download Triggered by Embedded FramesEPSS 2.2%CVE-2025-69200HIGHphpMyFAQ has unauthenticated config backup download via /api/setup/backupEPSS 2.1%CVE-2026-24421MEDIUMphpMyFAQ missing authorization exposes /api/setup/backup to any authenticated userEPSS 1.8%CVE-2024-28105HIGHphpMyFAQ's File Upload Bypass at Category Image Leads to RCEEPSS 1.5%CVE-2024-27299HIGHphpMyFAQ SQL Injection at "Save News"EPSS 1.2%CVE-2024-28107HIGHphpMyFAQ SQL injections at insertentry & saveentryEPSS 1.0%