← voltar
CVE-2026-46361

phpMyFAQ - Stored Cross-Site Scripting via raw Filter in search.twig

CVSS 8.2 HIGHEPSS 0.2%CWE-79
phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in search.twig where result.question and result.answerPreview are rendered with the raw filter, disabling autoescape protection. Attackers with FAQ editor privileges can inject HTML-entity-encoded payloads that bypass html_entity_decode(strip_tags()) processing in SearchController.php, executing arbitrary JavaScript in every visitor's browser context including administrators.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N
Produtos afetados
thorsten · phpmyfaq

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →