Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.9 PHP packages GHSA-rw77-vq4g-x3hp CVE-2026-56738 PKSA-5kfv-yxk9-ft5p PKSA-mq9q-wz1h-jkfd

phpMyFAQ: Authenticated SQL Injection in Stop Word Management (CVE-2026-56738)

An SQL injection flaw in phpMyFAQ's stop-word management feature allows an authenticated administrator to inject arbitrary SQL through the word-add function. Version 4.1.6 fixes the issue.

AI summary

A SQL injection vulnerability has been disclosed in phpMyFAQ, an open source FAQ web application. The issue affects the function used to add new stop words in the application's administration area and allows a user with administrative access to inject arbitrary SQL statements. The vendor has released version 4.1.6 to address the problem.

What happened

A SQL injection vulnerability was identified in phpMyFAQ's `StopWords::add()` method. This method builds a SQL `INSERT` statement using `sprintf()` and inserts the user-supplied stop word value directly into the query string without applying the application's database escaping function. A sibling method, `StopWords::update()`, which modifies an existing stop word, correctly escapes the same type of input, meaning the flaw is isolated to the add/insert code path.

Technical cause

The root cause is improper neutralization of special elements in an SQL command (CWE-89). Because the `add()` method does not escape the "word" parameter before inserting it into the SQL string, a crafted value can break out of the intended SQL string literal, allowing an attacker to append arbitrary SQL statements to the query.

Why it matters

An attacker who can inject arbitrary SQL through this path could drop database tables, exfiltrate data, or modify other rows in the database, potentially compromising the confidentiality and integrity of the entire phpMyFAQ installation's database.

Who is affected

Exploitation requires an authenticated administrator account with access to the stop-word management feature in phpMyFAQ. This is not an unauthenticated, remotely exploitable vulnerability; the attacker (or compromised admin account) must already have administrative privileges within the application.

Affected versions

The vulnerability affects the `phpmyfaq/phpmyfaq` and `thorsten/phpmyfaq` Composer packages in versions up to and including 4.1.5. Version 4.1.6 contains the fix.

Fixes and mitigation

The vendor has released version 4.1.6, which corrects the missing escaping in the `StopWords::add()` method. Site owners running affected versions should upgrade to 4.1.6.

Recommended action

Update phpMyFAQ to version 4.1.6 as soon as possible. In the interim, limit administrative access to trusted users only, since exploitation requires an authenticated administrative account with access to the stop-word management feature.

PatchBriefing score

4.9 / 10 · Medium

Official CVSS: 8.5

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Why this score

This vulnerability has a patchwire score of 4.9, driven primarily by its CVSS base score of 8.5, which reflects the high impact on data confidentiality and integrity once exploited. The score is moderated by the fact that exploitation requires authentication with administrative privileges (not unauthenticated or remotely exploitable without credentials), and there is no evidence of known exploitation, public exploit code, or an elevated EPSS likelihood of exploitation. A fix is available, which also limits further score elevation.

Affected versions

phpmyfaq/phpmyfaq <= 4.1.5
vulnerable
phpmyfaq/phpmyfaq <=4.1.5
vulnerable
≥ 4.1.6
patched
thorsten/phpmyfaq <= 4.1.5
vulnerable
thorsten/phpmyfaq <=4.1.5
vulnerable
≥ 4.1.6
patched

Reported fixes

The vendor has released version 4.1.6, which corrects the missing escaping in the `StopWords::add()` method. Site owners running affected versions should upgrade to 4.1.6.

How this was built

4 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • Packagist Security Advisories registry
  • Packagist Security Advisories registry
  • NVD (NIST) database
Unified report
phpMyFAQ: Authenticated SQL Injection in Stop Word Management (CVE-2026-56738)
1 article · 4 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email