phpmyfaq/phpmyfaq

Licenses: (LGPL-3.0 OR MIT) | Unknown | MPL-2.0

License

(LGPL-3.0 OR MIT)>=2.8.0-RC, <2.9.0-alpha3;
Unknown>=2.9.0-alpha3, <2.9.9;
MPL-2.0>=2.9.9;

Direct Vulnerabilities

Known vulnerabilities in the phpmyfaq/phpmyfaq package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Improper Privilege Management

<4.1.6
  • H
SQL Injection

<4.1.7
  • H
Missing Critical Step in Authentication

<4.1.7
  • M
Missing Authorization

<4.1.7
  • M
Insecure Temporary File

<4.1.7
  • M
Information Exposure

<4.1.7
  • H
Insufficient Logging

>=3.1.0, <4.1.7
  • H
Information Exposure

<4.1.7
  • M
Missing Authorization

<4.1.7
  • C
Replay Attack

<4.1.7
  • M
Arbitrary Argument Injection

>=4.2.0-alpha, <4.1.7
  • M
Missing Authorization

<4.1.7
  • H
External Control of File Name or Path

<4.1.6
  • M
Missing Authentication for Critical Function

<4.1.7
  • C
Brute Force

<4.1.7
  • M
SQL Injection

<4.2.0-alpha
  • C
Resources Downloaded over Insecure Protocol

<4.1.6
  • H
Directory Traversal

<4.1.6
  • H
Improper Privilege Management

<4.1.5
  • M
Directory Traversal

<4.1.5
  • M
Information Exposure

>=4.1.0, <4.1.5
  • H
Improper Privilege Management

<4.1.5
  • H
Unlock of a Resource that is not Locked

<4.1.4
  • H
Missing Authorization

<4.1.4
  • M
Use of Weak Hash

<4.1.4
  • H
Missing Authorization

<4.1.3
  • H
Insecure Default Initialization of Resource

<4.1.3
  • H
Weak Password Recovery Mechanism for Forgotten Password

<4.1.3
  • H
Weak Password Recovery Mechanism for Forgotten Password

<4.1.3
  • H
Incorrect Authorization

<4.1.2
  • H
Directory Traversal

<4.1.2
  • M
Cross-site Scripting (XSS)

<4.1.2
  • M
Missing Authorization

<4.1.2
  • H
Incorrect Authorization

<4.1.2
  • M
Cross-site Scripting (XSS)

<4.1.2
  • M
Incorrect Authorization

>=4.1.1, <4.1.2
  • M
Cross-site Scripting (XSS)

<4.1.2
  • C
Brute Force

<4.1.2
  • C
SQL Injection

<4.1.2
  • H
Improper Encoding or Escaping of Output

>=4.1.1, <4.1.2
  • H
SQL Injection

<4.1.2
  • M
Missing Authorization

<4.1.2
  • M
Improper Neutralization of Special Elements in Data Query Logic

<4.1.1
  • H
Directory Traversal

<4.1.1
  • M
Cross-site Scripting (XSS)

<4.1.1
  • H
Cross-site Scripting (XSS)

<4.1.1
  • M
Cross-site Scripting (XSS)

<4.1.1
  • H
SQL Injection

<4.0.14
  • M
Cross-site Scripting (XSS)

>=3.2.10, <4.0.2
  • M
Cross-site Scripting (XSS)

<2.9.9
  • M
Cross-site Scripting (XSS)

<2.9.7
  • M
Authentication Bypass

<2.9.7
  • H
Cross-site Request Forgery (CSRF)

<2.9.11
  • H
CSV Injection

<2.9.11