CVE-2026-76210

HIGH CVSS 4.0: 7.1 EPSS 0.37%
Updated Sep 01, 2026
PHP
Parameter Value
CVSS 7.1 (HIGH)
Affected Versions before 4.1.6
Fixed In 4.1.6
Type CWE-73 (External Control of File Name or Path)
Vendor PHP
Public PoC No

phpMyFAQ before 4.1.6 does not adequately sanitize HTML in FAQ answers before generating PDFs via TCPDF. An attacker with permission to create or edit FAQ content can embed an <img> tag whose src references a local file under the web root's content/ directory (e.g., content/core/config/database.php). When the PDF is generated, phpMyFAQ attempts to read the referenced file; because it is not a valid image the resulting error is converted into an uncaught exception whose stack trace discloses part of the file's contents to any user who triggers the PDF export.

By default the disclosed portion is truncated (zend.exception_string_param_max_len), but a larger configured value can result in disclosure of entire files, including database credentials.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Phpmyfaq Phpmyfaq
cpe:2.3:a:phpmyfaq:phpmyfaq:*:*:*:*:*:*:*:*
4.1.6