CVE-2026-66397
phpMyFAQ before 4.1.6 Path Traversal via category image deletion
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, allowing authenticated attackers to delete arbitrary files by exploiting insufficient sanitization in Image::delete(). Attackers can delete the database.php configuration file to disable the installation gate and access the public setup wizard to create new superadmin accounts.
| CWE | CWE-22 |
| Vendor | thorsten |
| Product | phpmyfaq |
| Published | Jul 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for thorsten phpmyfaq
Be the first to know when new unknown vulnerabilities affecting thorsten phpmyfaq are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
thorsten / phpMyFAQ
0 < 4.1.6
References
Credits
๐ ImDuong