HIGH
phpMyFAQ before 4.1.7 SQL Injection via Glossary
Published Aug 19, 2026
8.6
HIGHCVSS 4.0
EPSS 0.43%
Description
phpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the glossary create and update endpoints caused by truncating an escaped string before embedding it in a SQL literal. Authenticated users with glossary add or edit permissions can craft a payload with a dangling backslash to escape the closing quote and inject arbitrary SQL commands to read sensitive database information.
Affected products
-
Affected
- ≥ 0, < 4.1.7
Unaffected
- 4.1.7
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-62446 Advisory
- https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-79h3-6hxj-g98h exploitvendor-advisoryVendor Advisory
- https://www.vulncheck.com/advisories/phpmyfaq-before-sql-injection-via-glossary third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-62446 | Advisory | |
| https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-79h3-6hxj-g98h | exploitvendor-advisoryVendor Advisory | |
| https://www.vulncheck.com/advisories/phpmyfaq-before-sql-injection-via-glossary | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 19, 2026
Updated Aug 21, 2026
Reserved Aug 19, 2026
Link CVE-2026-76205
CISA Vulnrichment
Updated Aug 21, 2026
Red Hat
No data
GitHub
No data