github.com
https://github.com/thorsten/phpMyFAQ CVE-2026-34974
MEDIUM
phpMyFAQ: SVG Sanitizer Bypass via HTML Entity Encoding leads to Stored XSS and Privilege Escalation
Record summary
CVE-2026-34974 has a selected CVSS score of 5.4 (medium).
Description
phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the regex-based SVG sanitizer in phpMyFAQ (SvgSanitizer.php) can be bypassed using HTML entity encoding in javascript: URLs within SVG <a href> attributes. Any user with edit_faq permission can upload a malicious SVG that executes arbitrary JavaScript when viewed, enabling privilege escalation from editor to full admin takeover. This issue has been patched in version 4.1.1.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 2, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
phpMyFAQBrowse thorsten / phpMyFAQ | CVE List | < 4.1.1 | affected |
thorsten/phpmyfaqBrowse Packagist / thorsten/phpmyfaq | GitHub Advisory | Before 4.1.1 · Fixed in 4.1.1 | affected |
References
4github.com
https://github.com/thorsten/phpMyFAQ/releases/tag/4.1.1 github.comConfirmation
https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-5crx-pfhq-4hgg nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-34974