github.com
https://github.com/thorsten/phpMyFAQ CVE-2026-46363
MEDIUM
phpMyFAQ - Stored XSS in FAQ Question/Answer via Encode-Decode Bypass
Record summary
CVE-2026-46363 has a selected CVSS score of 5.1 (medium).
Description
phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in FAQ creation and update endpoints that bypass sanitization through encode-decode cycles. The vulnerability allows authenticated attackers with FAQ_ADD permission to inject malicious script tags via question or answer parameters, which execute in every visitor's browser when FAQ content is rendered with the raw Twig filter.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 15, 2026 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
phpmyfaqBrowse thorsten / phpmyfaqDefault status: unaffected | CVE List | Before 4.1.2 | affected |
| 4.1.2 | unaffected | ||
phpmyfaq/phpmyfaqBrowse Packagist / phpmyfaq/phpmyfaq | GitHub Advisory | Before 4.1.2 · Fixed in 4.1.2 | affected |
thorsten/phpmyfaqBrowse Packagist / thorsten/phpmyfaq | GitHub Advisory | Before 4.1.2 · Fixed in 4.1.2 | affected |
References
4GHSA Advisory GHSA-f5p7-2c9q-8896Vendor advisory
https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-f5p7-2c9q-8896 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-46363 VulnCheck Advisory: phpMyFAQ - Stored XSS in FAQ Question/Answer via Encode-Decode BypassThird-party advisory
https://www.vulncheck.com/advisories/phpmyfaq-stored-xss-in-faq-question-answer-via-encode-decode-bypass