Security Advisory 2026-10-09

Multiple vulnerabilities in phpMyFAQ

Issued on:
2026-10-09
Software:
phpMyFAQ <= 4.1.9
Risk:
High
Platforms:
all

The phpMyFAQ Team has learned of security issues that'd been discovered in phpMyFAQ 4.1.9 and earlier.

Description

High severity

The FAQ creation API POST /api/faq/create does not apply object-level authorization to the openQuestionID parameter, so an unauthenticated attacker can rewrite or delete any open question submitted by visitors.

Moderate severity

The PDF export fetches remote resources referenced in FAQ content without restricting the target, enabling server-side request forgery.

Solution

The phpMyFAQ Team has released the new phpMyFAQ versions 4.1.10 and 4.2.0-beta.2, which fix these vulnerabilities. All users of affected phpMyFAQ versions are encouraged to upgrade as soon as possible to one of these versions.

Workaround

There's no workaround except installing phpMyFAQ 4.1.10 or 4.2.0-beta.2.

Thanks

The phpMyFAQ team would like to thank hariprasanth9317-tech and YuHe-G for the responsible disclosures of these vulnerabilities.