Executive brief
Duplicate Advisory: phpMyFAQ: Stored XSS in FAQ Question/Answer via Encode-Decode Bypass of removeAttributes() Sanitization
Affected products
- Packagist phpmyfaq/phpmyfaq
- Packagist thorsten/phpmyfaq
Junglewise Threat Intelligence
Severity: low · CVSS 3.1 · Published 2026-05-15
Technologies: phpmyfaq/phpmyfaq (Packagist), thorsten/phpmyfaq (Packagist). Vendors: Packagist.
Duplicate Advisory: phpMyFAQ: Stored XSS in FAQ Question/Answer via Encode-Decode Bypass of removeAttributes() Sanitization