Vulnerabilidades em thorsten

140 resultados
Análise Vexday

Com 115 CVEs catalogadas e 24 surgidas nos últimos 90 dias, o vendor Thorsten apresenta um volume de vulnerabilidades recente que merece atenção contínua. A taxa de exploração ativa está abaixo da média geral do catálogo, com nenhuma entrada no CISA KEV, o que sugere menor pressão imediata de ataques em curso — embora 7 falhas de severidade crítica e 4 com PoC pública representem superfície de ataque concreta. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), indicando lacunas persistentes em validação e sanitização de entrada. A CVE mais perigosa no momento, CVE-2022-3766, registra EPSS de 0.0574, valor relativamente contido, mas que deve ser monitorado especialmente em ambientes onde atualizações não são aplicadas de forma sistemática.

CVE-2026-34973MEDIUMphpMyFAQ has a LIKE Wildcard Injection in Search.php — Unescaped % and _ Metacharacters Enable Broad Content DisclosureEPSS 0.3%CVE-2023-5317MEDIUMCross-site Scripting (XSS) - Stored in thorsten/phpmyfaqEPSS 0.3%CVE-2026-85587MEDIUMphpMyFAQ before 4.1.8 Incorrect Authorization via Admin PagesEPSS 0.3%CVE-2026-75920MEDIUMphpMyFAQ before 4.1.6 Information Disclosure via Backup ZIPEPSS 0.3%CVE-2026-76213CRITICALphpMyFAQ before 4.1.7 2FA Brute-Force via Session-Scoped ThrottleEPSS 0.3%CVE-2026-66398CRITICALphpMyFAQ before 4.1.6 Remote Code Execution via Configuration APIEPSS 0.3%CVE-2026-66397HIGHphpMyFAQ before 4.1.6 Path Traversal via category image deletionEPSS 0.3%CVE-2026-35675HIGHphpMyFAQ - Authentication Bypass via Missing Password Reset Token in /api/user/password/updateEPSS 0.3%CVE-2026-76212MEDIUMphpMyFAQ before 4.1.7 LIKE Wildcard Injection via PostgreSQLEPSS 0.3%CVE-2026-46362HIGHphpMyFAQ - Authorization Bypass in Admin Pages via Non-Terminating Permission CheckEPSS 0.3%CVE-2026-35671HIGHphpMyFAQ - Insecure Direct Object Reference in User Password APIEPSS 0.3%CVE-2026-76208HIGHphpMyFAQ 3.1.0 through 4.1.6 Authentication Bypass via LDAPEPSS 0.3%CVE-2026-85591HIGHphpMyFAQ before 4.1.8 Authentication Bypass via Unverified Password ChangeEPSS 0.3%CVE-2026-76214CRITICALphpMyFAQ before 4.1.7 WebAuthn Replay Attack via ChallengeEPSS 0.3%CVE-2026-76205HIGHphpMyFAQ before 4.1.7 SQL Injection via GlossaryEPSS 0.3%CVE-2023-5866MEDIUMSensitive Cookie in HTTPS Session Without 'Secure' Attribute in thorsten/phpmyfaqEPSS 0.3%CVE-2026-85589MEDIUMphpMyFAQ before 4.2.0-alpha.2 Missing Authorization via Dashboard APIEPSS 0.3%CVE-2025-68951MEDIUMphpMyFAQ has stored XSS in admin "List of users" via display_name HTML entity decoding (html_entity_decode) + Twig |rawEPSS 0.3%CVE-2026-45008HIGHphpMyFAQ - Path Traversal in Client::deleteClientFolder via URL ParameterEPSS 0.3%CVE-2026-32629MEDIUMphpMyFAQ: Stored XSS via Unsanitized Email Field in Admin FAQ EditorEPSS 0.3%