CVE-2026-85587: Thorsten Phpmyfaq

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content. Attackers with only add permissions can access news edit and FAQ translate endpoints to view unpublished content invisible to the public.

Affected products

  • Thorsten Phpmyfaq: before 4.1.8 (fixed in 4.1.8)

Published 2026-09-04. Last modified 2026-09-08.