Security Advisory 2026-10-09
Multiple vulnerabilities in phpMyFAQ
- Issued on:
- 2026-10-09
- Software:
- phpMyFAQ <= 4.1.9
- Risk:
- High
- Platforms:
- all
The phpMyFAQ Team has learned of security issues that'd been discovered in phpMyFAQ 4.1.9 and earlier.
Description
High severity
The FAQ creation API POST /api/faq/create does not apply object-level authorization to the openQuestionID parameter, so an unauthenticated attacker can rewrite or delete any open question submitted by visitors.
Moderate severity
The PDF export fetches remote resources referenced in FAQ content without restricting the target, enabling server-side request forgery.
Solution
The phpMyFAQ Team has released the new phpMyFAQ versions 4.1.10 and 4.2.0-beta.2, which fix these vulnerabilities. All users of affected phpMyFAQ versions are encouraged to upgrade as soon as possible to one of these versions.
Workaround
There's no workaround except installing phpMyFAQ 4.1.10 or 4.2.0-beta.2.
Thanks
The phpMyFAQ team would like to thank hariprasanth9317-tech and YuHe-G for the responsible disclosures of these vulnerabilities.