CVE Explorer
CVE-2025-68951
phpMyFAQ is an open source FAQ web application. Versions 4.0.14 and 4.0.15 have a stored cross-site scripting (XSS) vulnerability that allows an attacker to execute arbitrary JavaScript in an administrator’s browser by registering a user whose display name contains HTML entities. When an administrator views the admin user list, the payload is decoded server-side and rendered without escaping, resulting in script execution in the admin context. Version 4.0.16 contains a patch for the issue.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"phpMyFAQ","vendor":"thorsten","versions":[{"status":"affected","version":">= 4.0.14, < 4.0.16"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:fa02101f9394507ab877c480e9dc636bae77b28426fe79805d211a1e6dacb4ea · sha256:aa3e0f5780a7e9d0… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:fa02101f9394507ab877c480e9dc636bae77b28426fe79805d211a1e6dacb4ea · sha256:aa3e0f5780a7e9d0… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-79","description":"CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:fa02101f9394507ab877c480e9dc636bae77b28426fe79805d211a1e6dacb4ea · sha256:aa3e0f5780a7e9d0… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/thorsten/phpMyFAQ/commit/61829e83411f7b28bc6fd1052bfde54c32c6c370","tags":["x_refsource_MISC"],"url":"https://github.com/thorsten/phpMyFAQ/commit/61829e83411f7b28bc6fd1052bfde54c32c6c370"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:fa02101f9394507ab877c480e9dc636bae77b28426fe79805d211a1e6dacb4ea · sha256:aa3e0f5780a7e9d0… · /containers/cna/references/1
{"name":"https://github.com/thorsten/phpMyFAQ/commit/8211d1d25951b4c272443cfc3ef9c09b1363fd87","tags":["x_refsource_MISC"],"url":"https://github.com/thorsten/phpMyFAQ/commit/8211d1d25951b4c272443cfc3ef9c09b1363fd87"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:fa02101f9394507ab877c480e9dc636bae77b28426fe79805d211a1e6dacb4ea · sha256:aa3e0f5780a7e9d0… · /containers/cna/references/2
{"name":"https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-jv8r-hv7q-p6vc","tags":["x_refsource_CONFIRM"],"url":"https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-jv8r-hv7q-p6vc"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:fa02101f9394507ab877c480e9dc636bae77b28426fe79805d211a1e6dacb4ea · sha256:aa3e0f5780a7e9d0… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.