Medium · 5.3 PHP packages GHSA-8gpw-xvpf-hvx5 CVE-2026-56737 PKSA-tcxy-t63n-k6vh PKSA-p9tj-4psw-jkcc
phpMyFAQ: Two Critical Vulnerabilities Allow Administrator Account Takeover
Two vulnerabilities in phpMyFAQ (CVE-2026-56737 and CVE-2026-56736) can be combined or used independently to take over administrator accounts: a two-factor authentication bypass and a stored XSS flaw in the FAQ submission/review workflow. Updates are available.
- GitHub Advisory Database database 2w ago · view ↗
- Packagist Security Advisories registry 2w ago · view ↗
- Packagist Security Advisories registry 2w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- GitHub Advisory Database database 2w ago · view ↗
- Packagist Security Advisories registry 2w ago · view ↗
- Packagist Security Advisories registry 2w ago · view ↗
- NVD (NIST) database 2w ago · view ↗
AI summary
Two separate vulnerabilities have been disclosed in phpMyFAQ, an open source FAQ web application. The first allows an unauthenticated attacker to bypass the password factor of two-factor authentication (2FA) and take over any 2FA-enabled account, including administrators. The second is a stored cross-site scripting (XSS) flaw in the FAQ submission and admin review workflow that can lead to administrator session theft. Both issues have fixes available and are tracked under separate CVE identifiers.
What happened
Two distinct security issues were disclosed in phpMyFAQ. CVE-2026-56737 is an authentication bypass in the public two-factor authentication verification flow: an unauthenticated attacker can submit an account's numeric user ID together with a valid or brute-forced six-digit TOTP code, without first supplying the account password, and gain access to the account. CVE-2026-56736 is a stored XSS vulnerability where a user-submitted FAQ entry containing injected JavaScript executes in an administrator's browser when the administrator reviews or edits that entry, enabling session theft and admin account takeover.
Technical cause
For CVE-2026-56737, the 2FA verification endpoint does not require a session established through successful password authentication before accepting a TOTP code, so the password factor can be skipped entirely. For CVE-2026-56736, the application calls html_entity_decode() after strip_tags() has already processed input, which converts encoded HTML entities back into executable HTML. The admin template then renders this content using Twig's |raw filter without further output sanitization, allowing injected script to execute in the administrator's browser.
Why it matters
Both vulnerabilities can result in full compromise of administrator accounts. The 2FA bypass (CVE-2026-56737) removes the protection that 2FA is meant to provide, allowing account takeover by an unauthenticated attacker who only needs a numeric user ID and a TOTP code. The stored XSS (CVE-2026-56736) can be triggered through the public FAQ submission form by any unauthenticated or low-privileged user, and executes with administrator privileges once reviewed, enabling session theft and subsequent administrative control of the application.
Affected versions
CVE-2026-56737 affects phpMyFAQ (packages thorsten/phpmyfaq and phpmyfaq/phpmyfaq) versions 3.2.0 up to but not including 4.1.6. CVE-2026-56736 affects versions before 4.2.0-alpha (the description notes it affects all versions prior to that release).
Fixes and mitigation
CVE-2026-56737 is fixed in version 4.1.6, which binds TOTP verification to a session established after successful password authentication and limits failed TOTP attempts. No official workaround is documented for this issue. CVE-2026-56736 is fixed in version 4.2.0-alpha.
Recommended action
Administrators running phpMyFAQ should upgrade to version 4.1.6 or later to remediate the 2FA bypass, and to version 4.2.0-alpha or later to remediate the stored XSS issue. Given that no workaround exists for the 2FA bypass, upgrading is the only documented remediation path.
PatchBriefing score
5.3 / 10 · Medium
Official CVSS: 8.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Why this score
Both vulnerabilities carry a high CVSS base score (8.1 for CVE-2026-56737 and 8.2 for CVE-2026-56736), reflecting their potential for complete compromise of confidentiality and integrity through administrator account takeover. The computed PatchBriefing scores (5.3 and 5.1) reflect the CVSS base score combined with the fact that both issues are exploitable by unauthenticated, remote attackers, with no evidence currently of active exploitation, public exploit code, or EPSS data indicating elevated near-term exploitation likelihood.
Affected versions
- thorsten/phpmyfaq >= 3.2.0, < 4.1.6
- vulnerable
- thorsten/phpmyfaq >=3.2.0,<4.1.6
- vulnerable
- ≥ 4.1.6
- patched
- phpmyfaq/phpmyfaq >= 3.2.0, < 4.1.6
- vulnerable
- phpmyfaq/phpmyfaq >=3.2.0,<4.1.6
- vulnerable
- ≥ 4.1.6
- patched
- thorsten/phpmyfaq < 4.2.0-alpha
- vulnerable
- thorsten/phpmyfaq <4.2.0-alpha
- vulnerable
- ≥ 4.2.0-alpha
- patched
- phpmyfaq/phpmyfaq < 4.2.0-alpha
- vulnerable
- phpmyfaq/phpmyfaq <4.2.0-alpha
- vulnerable
- ≥ 4.2.0-alpha
- patched
Reported fixes
CVE-2026-56737 is fixed in version 4.1.6, which binds TOTP verification to a session established after successful password authentication and limits failed TOTP attempts. No official workaround is documented for this issue. CVE-2026-56736 is fixed in version 4.2.0-alpha.
How this was built
8 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
Packagist Security Advisories registry
-
Packagist Security Advisories registry
-
NVD (NIST) database
-
GitHub Advisory Database database
-
Packagist Security Advisories registry
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email