CVE-2026-47132

MEDIUM Status: Deferred

CVSS Scores

CVSS v3.x Base Score
5.4
MEDIUM

Description

phpMyFAQ is an open source FAQ web application. Prior to version 4.2.0-alpha, an authenticated SQL LIKE wildcard injection vulnerability in phpMyFAQ’s chat user search allows any logged-in user to bypass the intended display-name search filter and enumerate active users. The endpoint escapes SQL string syntax but does not escape `%` and `_`, which remain active `LIKE` wildcards. Version 4.2.0-alpha patches the issue.

Published
September 24, 2026 5:17 PM
Last Modified
September 24, 2026 6:17 PM
Source
[email protected]

Weaknesses (CWE)

CWE-20 CWE-89 CWE-200

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.