Improper Neutralization of Argument Delimiters in a Command in phpMyFAQ - #VU140891
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper neutralization of wildcard characters in PostgreSQL search backend when processing user-supplied search terms. A remote attacker can submit search terms containing % or _ characters to cause a denial of service.
Only deployments using the native PostgreSQL pgsql extension backend are vulnerable; the PDO PostgreSQL backend is not affected.