CVE-2018-16651: Phpmyfaq

High severity, CVSS 7.2. EPSS: 1.4% chance of exploitation in the next 30 days.

The admin backend in phpMyFAQ before 2.9.11 allows CSV injection in reports.

Affected products

  • Phpmyfaq Phpmyfaq: before 2.9.11 (fixed in 2.9.11)

Published 2018-09-07. Last modified 2026-06-17.