Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

thorsten/phpmyfaq — Vulnerabilities & Security Advisories 69

All 69 CVE vulnerabilities found in thorsten/phpmyfaq, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities associated with the thorsten/phpmyfaq product, a popular open-source FAQ application written in PHP. It aggregates known weakness entries that affect this specific software package, covering data from initial discoveries up to the present day. The collection includes various flaw types such as cross-site scripting, path traversal, and insecure direct object references that have been identified in different releases of the application. By consolidating these records, the page allows security professionals and system administrators to track a vendor's advisory history and monitor the evolution of its security posture over time. Visitors can also explore the specific technical characteristics of each weakness class to better understand how these flaws manifest within the codebase. This resource serves as a historical record for the product, enabling users to look up past vulnerability details, assess the impact of specific CVEs on their deployments, and identify patterns in reported security issues. The information is structured to facilitate easy searching and filtering, helping stakeholders quickly locate relevant data without sifting through unstructured reports. Maintaining an accurate and comprehensive record of these defects supports better risk management and informed decision-making regarding software updates and mitigation strategies for users relying on this FAQ tool.

Vendor: thorsten

CVE IDTitleCVSSSeverityPublished
CVE-2023-6890 Cross-site Scripting (XSS) - Stored in thorsten/phpmyfaq CWE-79 5.4 -2023-12-16
CVE-2023-6889 Cross-site Scripting (XSS) - Stored in thorsten/phpmyfaq CWE-79 5.4 -2023-12-16
CVE-2023-5866 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in thorsten/phpmyfaq CWE-614 5.3 -2023-10-31
CVE-2023-5867 Cross-site Scripting (XSS) - Stored in thorsten/phpmyfaq CWE-79 5.4 -2023-10-31
CVE-2023-5865 Insufficient Session Expiration in thorsten/phpmyfaq CWE-613 9.4 -2023-10-31
CVE-2023-5864 Cross-site Scripting (XSS) - Stored in thorsten/phpmyfaq CWE-79 5.4 -2023-10-31
CVE-2023-5863 Cross-site Scripting (XSS) - Reflected in thorsten/phpmyfaq CWE-79 6.1 -2023-10-31
CVE-2023-5320 Cross-site Scripting (XSS) - DOM in thorsten/phpmyfaq CWE-79 6.1 -2023-09-30
CVE-2023-5317 Cross-site Scripting (XSS) - Stored in thorsten/phpmyfaq CWE-79 5.4 -2023-09-30
CVE-2023-5316 Cross-site Scripting (XSS) - DOM in thorsten/phpmyfaq CWE-79 6.1 -2023-09-30
CVE-2023-5319 Cross-site Scripting (XSS) - Stored in thorsten/phpmyfaq CWE-79 5.4 -2023-09-30
CVE-2023-5227 Unrestricted Upload of File with Dangerous Type in thorsten/phpmyfaq CWE-434 8.8 -2023-09-30
CVE-2023-4007 Cross-site Scripting (XSS) - Stored in thorsten/phpmyfaq CWE-79 5.4 -2023-07-31
CVE-2023-4006 Improper Neutralization of Formula Elements in a CSV File in thorsten/phpmyfaq CWE-1236 8.8 -2023-07-31
CVE-2023-3469 Cross-site Scripting (XSS) - Reflected in thorsten/phpmyfaq CWE-79 6.1 -2023-06-30
CVE-2023-2998 Cross-site Scripting (XSS) - Stored in thorsten/phpmyfaq CWE-79 5.4 -2023-05-31
CVE-2023-2999 Cross-site Scripting (XSS) - Stored in thorsten/phpmyfaq CWE-79 5.4 -2023-05-31
CVE-2023-2752 Cross-site Scripting (XSS) - Stored in thorsten/phpmyfaq CWE-79 5.4 -2023-05-17
CVE-2023-2753 Cross-site Scripting (XSS) - Stored in thorsten/phpmyfaq CWE-79 5.4 -2023-05-17
CVE-2023-2550 Cross-site Scripting (XSS) - Stored in thorsten/phpmyfaq CWE-79 5.4 -2023-05-05
CVE-2023-2427 Cross-site Scripting (XSS) - Reflected in thorsten/phpmyfaq CWE-79 6.1 -2023-05-05
CVE-2023-2429 Improper Access Control in thorsten/phpmyfaq CWE-284 5.4 -2023-04-30
CVE-2023-2428 Cross-site Scripting (XSS) - Stored in thorsten/phpmyfaq CWE-79 5.4 -2023-04-30
CVE-2023-1875 Cross-site Scripting (XSS) - Stored in thorsten/phpmyfaq CWE-79 5.4 Medium2023-04-22
CVE-2023-1878 Cross-site Scripting (XSS) - Stored in thorsten/phpmyfaq CWE-79 5.4 -2023-04-05
CVE-2023-1880 Cross-site Scripting (XSS) - Reflected in thorsten/phpmyfaq CWE-79 6.1 -2023-04-05
CVE-2023-1879 Cross-site Scripting (XSS) - Stored in thorsten/phpmyfaq CWE-79 5.4 -2023-04-05
CVE-2023-1882 Cross-site Scripting (XSS) - DOM in thorsten/phpmyfaq CWE-79 5.4 -2023-04-05
CVE-2023-1758 Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in thorsten/phpmyfaq CWE-75 8.2 -2023-04-05
CVE-2023-1757 Cross-site Scripting (XSS) - Stored in thorsten/phpmyfaq CWE-79 5.4 -2023-04-05

All 69 known CVE vulnerabilities affecting thorsten/phpmyfaq with full Chinese analysis, references, and POCs where available.