
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34973 is a LIKE Wildcard Injection vulnerability in phpMyFAQ's searchCustomPages() method that enables unauthenticated information disclosure. The flaw exists in phpmyfaq/src/phpMyFAQ/Search.php and affects phpMyFAQ version 4.1.0; it was patched in version 4.1.1. The vulnerability was published on March 31, 2026, and added to the GitHub Advisory Database on April 1, 2026. It carries a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 base score of 6.9 (Medium) (GitHub Advisory, phpMyFAQ Advisory).
The root cause is classified as CWE-943 (Improper Neutralization of Special Elements in Data Query Logic). The searchCustomPages() method sanitizes user-supplied search terms using mysqli::real_escape_string() (via the internal escape() wrapper), which correctly escapes SQL string delimiters such as single quotes and backslashes but does not escape the SQL LIKE metacharacters % (match any sequence) and _ (match any single character). The sanitized term is then directly interpolated into a LIKE '%<term>%' clause for both page_title and content columns. An unauthenticated attacker can bypass the only other guard — a strlen <= 2 filter — by submitting a 3-character payload such as _%_, which causes the backend to execute WHERE (page_title LIKE '%_%_%' OR content LIKE '%_%_%'), matching every record in the faqcustompages table (GitHub Advisory, phpMyFAQ Advisory).
Successful exploitation allows an unauthenticated remote attacker to enumerate and disclose all custom page content stored in the faqcustompages database table, regardless of the intended search scope restrictions. The impact is limited to confidentiality — there is no integrity or availability impact — but sensitive content intended to be restricted or unpublished could be exposed to any internet user. There is no evidence of lateral movement potential or privilege escalation beyond content disclosure (GitHub Advisory).
A concrete proof-of-concept (PoC) is publicly available in the GitHub Security Advisory, providing step-by-step reproduction instructions against a live phpMyFAQ deployment (phpMyFAQ Advisory). No authentication is required, and exploitation requires only a standard HTTP request to the publicly accessible search endpoint. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.091% (0.114% per GitHub Advisory), placing it in the 30th percentile for exploitation likelihood.
/search or similar), which requires no authentication by default._%_ (underscore, percent, underscore), to bypass the strlen <= 2 filter.GET /search?q=_%_).WHERE (page_title LIKE '%_%_%' OR content LIKE '%_%_%'), which matches all custom pages with at least one character in their title or content, returning the full set of custom page records.faqcustompages table that would not be returned by a normal, specific search query (GitHub Advisory, phpMyFAQ Advisory).%, _, or combinations such as _%_ in the query parameter; high volume of search requests returning large result sets from unauthenticated sources.q=_%_, q=te%25t, q=a_b) from the same IP address in rapid succession; application logs showing broad database result sets returned for search queries.LIKE '%_%_%' or similar wildcard-heavy patterns in faqcustompages table queries originating from the web application user.Upgrade phpMyFAQ to version 4.1.1, which was released on March 31, 2026, and addresses this vulnerability (phpMyFAQ Release). As a workaround prior to patching, operators can apply manual escaping of LIKE metacharacters before interpolation using: $word = str_replace(['\\', '%', '_'], ['\\\\', '\\%', '\\_'], $word);. Alternatively, refactoring the search to use parameterized queries with properly escaped LIKE values eliminates the class of vulnerability entirely (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."