github.com
https://github.com/thorsten/phpMyFAQ CVE-2026-46359
HIGH
phpMyFAQ - SQL Injection in CurrentUser::setTokenData via Unescaped OAuth Token Fields
Record summary
CVE-2026-46359 has a selected CVSS score of 7.7 (high).
Description
phpMyFAQ before 4.1.2 contains a sql injection vulnerability in CurrentUser::setTokenData that allows authenticated attackers to execute arbitrary SQL by injecting malicious OAuth token claims. Attackers with Azure AD accounts containing SQL metacharacters in display names or JWT claims can break out of string literals and execute arbitrary database queries.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 15, 2026 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
phpmyfaqBrowse thorsten / phpmyfaqDefault status: unaffected | CVE List | Before 4.1.2 | affected |
| 4.1.2 | unaffected | ||
phpmyfaq/phpmyfaqBrowse Packagist / phpmyfaq/phpmyfaq | GitHub Advisory | Before 4.1.2 · Fixed in 4.1.2 | affected |
thorsten/phpmyfaqBrowse Packagist / thorsten/phpmyfaq | GitHub Advisory | Before 4.1.2 · Fixed in 4.1.2 | affected |
References
4GHSA Advisory GHSA-pm8c-3qq3-72w7Vendor advisory
https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-pm8c-3qq3-72w7 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-46359 VulnCheck Advisory: phpMyFAQ - SQL Injection in CurrentUser::setTokenData via Unescaped OAuth Token FieldsThird-party advisory
https://www.vulncheck.com/advisories/phpmyfaq-sql-injection-in-currentuser-settokendata-via-unescaped-oauth-token-fields