Junglewise Threat Intelligence

CVE-2026-46360: phpMyFAQ stored XSS in SvgSanitizer via entity decoding bypass

CVE-2026-46360 · Severity: medium · CVSS 5.4 · Published 2026-05-15

Technologies: phpmyfaq/phpmyfaq (Packagist), Thorsten phpMyFAQ, thorsten/phpmyfaq (Packagist). Vendors: Packagist, Thorsten.

Executive brief

phpMyFAQ, an open-source FAQ software, is vulnerable to a security flaw where malicious images can be used to execute unauthorized code. An attacker with permission to upload images can bypass security filters by using specially encoded SVG files. If another user or administrator clicks on the malicious image, the attacker could steal login sessions, escalate their own privileges, or access sensitive configuration data.

Technical details

A stored XSS vulnerability exists in phpMyFAQ due to an entity decoding depth limit in SvgSanitizer::decodeAllEntities(). The sanitizer only performs 5 iterations of recursive decoding; by nesting 'javascript:' URIs within 5 or more levels of '&' encoding, an attacker can bypass the isSafe() check. When the SVG is served with an 'image/svg+xml' MIME type, the browser's XML parser fully resolves the remaining entities, resulting in a functional 'javascript:' link. Exploitation requires an authenticated user with FAQ_EDIT permissions to upload the file and a victim to click the malicious element. This has been patched in version 4.1.2.

Affected products

  • thorsten phpMyFAQ <= 4.1.1

Timeline

  • 2026-04-28: disclosed
  • 2026-05-06: advisory
  • 2026-04-28: patched: Version 4.1.2 released

References

Related threats