CVE-2026-85593
Dashboard / Vulnerabilities / CVE-2026-85593
Summary: phpMyFAQ before 4.1.8 Stored XSS via html_entity_decode
Details: phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting vulnerability in FaqHelper::convertOldInternalLinks() that calls html_entity_decode() on sanitized FAQ content, reversing entity-encoding protection. Authenticated users with FAQ editing privileges can inject JavaScript payloads that execute in the browsers of all users viewing the affected FAQ pages.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85593.json, https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-x6qj-5jhf-xgpm, https://nvd.nist.gov/vuln/detail/CVE-2026-85593, https://www.vulncheck.com/advisories/phpmyfaq-before-4.1.8-stored-xss-via-html-entity-decode
Affected packages
Package
Name:
Purl:
