Cross-site scripting in phpMyFAQ - #VU130122
Published: May 5, 2026
phpMyFAQ
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in the FAQ creation and update endpoints and Twig rendering templates when processing crafted FAQ question or answer content. A remote user can submit specially crafted FAQ content to execute arbitrary script in a victim's browser.
User interaction is required when a victim views the compromised FAQ entry or related search results.