CVE-2026-35672

HIGH

phpMyFAQ - Authentication Bypass via Empty API Token

Title source: cna
STIX 2.1

Description

phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in API v4.0 where the default empty api.apiClientToken allows unauthenticated users to create and modify FAQ entries. Attackers can send an empty x-pmf-token header to bypass token validation and inject malicious content via POST endpoints /api/v4.0/faq/create, /api/v4.0/category, and /api/v4.0/question.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory
GHSA Advisory GHSA-gp95-j463-vv28
https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-gp95-j463-vv28
Third Party Advisory third-party-advisory
VulnCheck Advisory: phpMyFAQ - Authentication Bypass via Empty API Token
https://www.vulncheck.com/advisories/phpmyfaq-authentication-bypass-via-empty-api-token

Scores

CVSS v3 7.5
EPSS 0.0038
EPSS Percentile 29.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-1188
Status published
Products (4)
phpmyfaq/phpmyfaq 0 - 4.1.3Packagist
thorsten/phpMyFAQ < 4.1.3
thorsten/phpmyfaq 0 - 4.1.3Packagist
thorsten/phpMyFAQ 4.1.3
Published May 28, 2026
Tracked Since May 28, 2026