Vendor
Thorsten vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 41 vulnerabilities in Thorsten: 1 in the last 7 days and 8 in the last 90 days, 4 of them critical and 0 exploited in the wild. The most recent, CVE-2026-47132, was published on 24 September 2026. 1 technology has a page of its own.
- Last 7 days
- 1
- Last 90 days
- 8
- Critical, all time
- 4
- Exploited in the wild
- 0
About Thorsten
Thorsten Rinne is the lead developer and maintainer of the phpMyFAQ project.
Thorsten technologies
Latest Thorsten vulnerabilities
- CVE-2026-47132: phpMyFAQ is an open source FAQ web application. Prior to version 4.2.0-alpha, an authenticated SQL LIKE wildcard injection…mediumCVSS 5.4EPSS 0.3%
- CVE-2026-85592: phpMyFAQ authorization bypass in question creation endpointlowCVSS 3.7EPSS 0.3%
- CVE-2026-85590: phpMyFAQ two-factor authentication bypass via insufficient re-authenticationinfoCVSS 7.1EPSS 0.5%
- CVE-2026-85588: phpMyFAQ sensitive information disclosure in user data exportinfoCVSS 5.3EPSS 0.5%
- phpMyFAQ privilege escalation in GroupController::updatePermissionshighCVSS 8.8
- CVE-2026-66399: thorsten phpMyFAQ privilege escalation in GroupControllermediumCVSS 6.5
- CVE-2026-66398: thorsten phpMyFAQ remote code execution in configuration APIinfoCVSS 9.4
- CVE-2026-66397: phpMyFAQ path traversal in category image deletioninfoCVSS 8.6
- phpMyFAQ privilege escalation via incomplete fix in UserController APIhighCVSS 8.1
- CVE-2026-49205: phpMyFAQ missing authorization in API write endpointsmediumCVSS 6.5EPSS 0.4%
- CVE-2026-48488: phpMyFAQ weak cryptographic hash for attachment passwordsmediumCVSS 4EPSS 0.3%
- CVE-2026-35676: phpMyFAQ unauthenticated password reset in user password update APIhighCVSS 8.2EPSS 0.3%
- CVE-2026-35675: phpMyFAQ authentication bypass in password reset APIhighCVSS 8.2EPSS 0.5%
- CVE-2026-35672: phpMyFAQ authentication bypass in REST API v4.0highCVSS 7.5EPSS 0.6%
- CVE-2026-35671: phpMyFAQ IDOR in admin API user password endpointhighCVSS 8.8
- phpMyFAQ account takeover via weak password recovery mechanismhighCVSS 8.2
- phpMyFAQ auth bypass via default empty API tokenhighCVSS 7.5
- phpMyFAQ IDOR privilege escalation in Admin API password resethighCVSS 8.8
- phpMyFAQ weak password recovery in UnauthorizedUserControllerhighCVSS 8.2
- phpMyFAQ SQL injection in CurrentUser::setTokenDatahighCVSS 7.5
- phpMyFAQ stored XSS in search result renderingmediumCVSS 6.9
- phpMyFAQ 2FA bypass via unauthenticated brute-force in admin check endpointcriticalCVSS 9.1
- phpMyFAQ missing authorization in Admin API configuration endpointsmediumCVSS 4.3
- phpMyFAQ authorization bypass in AbstractAdministrationControllermediumCVSS 6.5
- phpMyFAQ information disclosure via solution ID permission bypasshighCVSS 7.5
Most severe Thorsten vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-46364: phpMyFAQ SQL injection in BuiltinCaptcha via User-Agent headercriticalCVSS 9.8EPSS 2.1%
- phpMyFAQ SQL injection in BuiltinCaptcha via User-Agent headercriticalCVSS 9.8
- CVE-2026-45010: thorsten phpMyFAQ 2FA bypass via brute-force in /admin/checkcriticalCVSS 9.1EPSS 0.6%
- phpMyFAQ 2FA bypass via unauthenticated brute-force in admin check endpointcriticalCVSS 9.1
- phpMyFAQ privilege escalation in GroupController::updatePermissionshighCVSS 8.8
- CVE-2026-35671: phpMyFAQ IDOR in admin API user password endpointhighCVSS 8.8
- phpMyFAQ IDOR privilege escalation in Admin API password resethighCVSS 8.8
- CVE-2026-35675: phpMyFAQ authentication bypass in password reset APIhighCVSS 8.2EPSS 0.5%
- CVE-2026-35676: phpMyFAQ unauthenticated password reset in user password update APIhighCVSS 8.2EPSS 0.3%
- phpMyFAQ account takeover via weak password recovery mechanismhighCVSS 8.2
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 3 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 1 | 0 | |
| 31 Aug 2026 | 3 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 1 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/thorsten.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Thorsten vulnerabilities", https://junglewise.ai/threats/vendors/thorsten, 26 September 2026.