phpMyFAQ, Information Disclosure via Public API, CVE-2026-57994 (Medium) -DC-Aug2026-1881

Listen to this Post

A vulnerability in phpMyFAQ versions 4.1.0 through 4.1.4 allows unauthenticated access to inactive (draft or review-only) FAQ content through public API endpoints. The issue stems from an inconsistent application of the `active = ‘yes’` filter across different API routes.
In phpMyFAQ 4.1.4, while the `GET /api/v3.1/faqs/{categoryId}` endpoint correctly hides inactive FAQs, two other public API endpoints do not. The `GET /api/v3.1/faq/{categoryId}/{faqId}` endpoint returns the full and answer of an inactive FAQ. Similarly, the `GET /api/v3.1/faqs/tags/{tagId}` and `GET /api/v4.0/faqs/tags/{tagId}` endpoints return the inactive FAQ’s and a preview of its answer.
This occurs because the `FaqController::getByTagId()` method retrieves FAQ IDs via `Tags::getFaqsByTagId()` and then calls Faq::getFaqsByIds(). The `Faq::getFaqsByIds()` method filters by record ID, language, and permission, but critically, it does not filter by the `active` status or publication date windows. This allows it to return the s and previews of inactive FAQs. The vulnerability is fixed in version 4.1.5.

DailyCVE Form:

Platform: phpMyFAQ
Version: 4.1.0-4.1.4
Vulnerability: Info Disclosure
Severity: Medium
Date: 2026-07-10

Prediction: Already Patched (4.1.5)

What Undercode Say:

Analytics & Commands

The following bash commands can be used to reproduce the vulnerability locally, as demonstrated in the official proof-of-concept (PoC).

Navigate to the phpMyFAQ 4.1.4 source directory
cd /path/to/phpMyFAQ-4.1.4
Ensure dependencies are installed
composer install
Run the PoC script
php path/to/poc_phpmyfaq_414_inactive_faq_api_exposure.php /path/to/phpMyFAQ-4.1.4

The expected output from a successful reproduction is:

VERDICT: reproduced inactive FAQ exposure through public API controller paths.

Exploit: (Educational Purposes!)

The vulnerability can be exploited by sending unauthenticated `GET` requests to specific API endpoints. An attacker with knowledge of a categoryId, faqId, or `tagId` can retrieve inactive FAQ content.
Direct Access: `GET /api/v3.1/faq/{categoryId}/{faqId}` – Returns the full and answer of the inactive FAQ.
Tag-Based Access: `GET /api/v3.1/faqs/tags/{tagId}` – Returns the and answer preview of inactive FAQs associated with the tag.
Tag-Based Access (v4): `GET /api/v4.0/faqs/tags/{tagId}` – Also returns the and answer preview, even when `api.onlyActiveFaqs=true` is set.

Protection:

The primary and most effective protection against this vulnerability is to upgrade to phpMyFAQ version 4.1.5 or later. This version implements a consistent public visibility check across all public FAQ API routes.

Impact:

Successful exploitation of this vulnerability leads to the unauthorized disclosure of inactive FAQ content. This content, intended to be non-public (e.g., drafts, review-only items), may contain sensitive information.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top