๐Ÿ” CVE Alert

CVE-2026-66398

UNKNOWN 0.0

phpMyFAQ before 4.1.6 Remote Code Execution via Configuration API

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated administrators with CONFIGURATION_EDIT and ATTACHMENT_ADD privileges to write arbitrary PHP files by manipulating the upgrade.lastDownloadedPackage setting. Attackers can upload a malicious ZIP file as an attachment, point the updater configuration to its stored path, and extract it into the application root to achieve code execution as the web server user.

CWE CWE-494
Vendor thorsten
Product phpmyfaq
Published Jul 27, 2026
Last Updated Jul 27, 2026
Stay Ahead of the Next One

Get instant alerts for thorsten phpmyfaq

Be the first to know when new unknown vulnerabilities affecting thorsten phpmyfaq are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

thorsten / phpMyFAQ
0 < 4.1.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-4fv7-8rr6-rf2w vulncheck.com: https://www.vulncheck.com/advisories/phpmyfaq-before-remote-code-execution-via-configuration-api

Credits

๐Ÿ” ImDuong