Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-76205

phpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the glossary create and update endpoints caused by truncating an escaped string before embedding it in a SQL literal. Authenticated users with glossary add or edit permissions can craft a payload with a dangling backslash to escape the closing quote and inject arbitrary SQL commands to read sensitive database information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 13.7%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2026-76205


Contact Us

Shodan ® - All rights reserved