Improper control of interaction frequency in phpMyFAQ - CVE-2026-85586
Published: August 21, 2026 / Updated: September 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to submit forged open questions and trigger notification emails.
The vulnerability exists due to improper control of interaction frequency in the open-question submission endpoint when processing requests with the store=now parameter. A remote attacker can send a specially crafted request to submit forged open questions and trigger notification emails.
Only instances with anonymous question submission enabled are vulnerable.