/Vulnerability Library

phpMyFAQ <= 4.1.1 - SQL Injection

CVE-2026-46364
Verified

Description

phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector() and BuiltinCaptcha::saveCaptcha() methods that interpolate unsanitized User-Agent headers into DELETE and INSERT queries. Unauthenticated attackers can exploit the public GET /api/captcha endpoint by crafting malicious User-Agent headers to perform time-based blind SQL injection, extracting sensitive data including user credentials, admin tokens, and SMTP credentials from the database.

Severity

Critical

CVSS Score

9.8

Exploit Probability

2%

Published Date

June 4, 2026

Template Author

dhiyaneshdk

CVE-2026-46364.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE ID:
cwe-89

References

https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-289f-fq7w-6q2whttps://www.phpmyfaq.dehttp://nvd.nist.gov/vuln/detail/CVE-2026-46364

Remediation Steps

Upgrade phpMyFAQ to version 4.1.2 or later.