Junglewise Threat Intelligence

CVE-2026-46363: phpMyFAQ stored XSS in FAQ creation and update endpoints

CVE-2026-46363 · Severity: medium · CVSS 5.4 · Published 2026-05-15

Technologies: phpmyfaq/phpmyfaq (Packagist), Thorsten phpMyFAQ, thorsten/phpmyfaq (Packagist). Vendors: Packagist, Thorsten.

Executive brief

phpMyFAQ, an open-source FAQ software, contains a vulnerability that allows users with FAQ creation permissions to inject malicious scripts into FAQ entries. When other users or administrators view these entries, the scripts execute in their browsers, potentially leading to account takeover, session hijacking, or the display of fraudulent content. This risk is particularly high for organizations where multiple contributors manage the knowledge base.

Technical details

A Stored XSS vulnerability exists in phpMyFAQ's FAQ creation and update endpoints within `FaqController.php`. The application uses a flawed sanitization chain where input is first HTML-encoded via `FILTER_SANITIZE_SPECIAL_CHARS`, but then immediately decoded using `html_entity_decode()`. The subsequent call to `Filter::removeAttributes()` only strips specific HTML attributes but fails to filter dangerous tags like `<script>`, `<iframe>`, or `<object>`. Furthermore, the Twig templates (`faq.twig` and `search.twig`) use the `|raw` filter, which prevents auto-escaping during rendering. An authenticated attacker with `FAQ_ADD` permissions can exploit this to execute arbitrary JavaScript in the context of any user viewing the FAQ. The issue is fixed in version 4.1.2.

Affected products

  • thorsten phpMyFAQ <= 4.1.1

Timeline

  • 2026-04-28: disclosed
  • 2026-05-06: advisory: GitHub Advisory published
  • 2026-04-28: patched: Version 4.1.2 released

References

Related threats