github.com
https://github.com/thorsten/phpMyFAQ CVE-2026-46367
HIGH
phpMyFAQ - Stored XSS via Utils::parseUrl() in Comment Rendering
Record summary
CVE-2026-46367 has a selected CVSS score of 8.3 (high).
Description
phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in Utils::parseUrl() that allows authenticated users to inject JavaScript via malformed URLs in comments. Attackers can craft URLs with unescaped quotes to inject event handlers, stealing admin session cookies and achieving full application takeover when visitors view affected FAQ pages.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 16, 2026 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
phpmyfaqBrowse thorsten / phpmyfaqDefault status: unaffected | CVE List | 4.1.1 to < 4.1.2 | affected |
| 4.1.2 | unaffected | ||
phpmyfaq/phpmyfaqBrowse Packagist / phpmyfaq/phpmyfaq | GitHub Advisory | 4.1.1 | affected |
| 4.1.1 to < 4.1.2 · Fixed in 4.1.2 | affected | ||
thorsten/phpmyfaqBrowse Packagist / thorsten/phpmyfaq | GitHub Advisory | 4.1.1 | affected |
| 4.1.1 to < 4.1.2 · Fixed in 4.1.2 | affected |
References
4GHSA Advisory GHSA-9525-27vj-c8r8Vendor advisory
https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-9525-27vj-c8r8 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-46367 VulnCheck Advisory: phpMyFAQ - Stored XSS via Utils::parseUrl() in Comment RenderingThird-party advisory
https://www.vulncheck.com/advisories/phpmyfaq-stored-xss-via-utils-parseurl-in-comment-rendering