CVE-2026-34974: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34974 is a Stored Cross-Site Scripting (XSS) vulnerability in phpMyFAQ's SVG sanitizer (SvgSanitizer.php) that allows privilege escalation from editor to full administrator. The flaw affects all phpMyFAQ versions up to and including 4.1.0, and was introduced with the SvgSanitizer class on 2026-01-15. It was published by the maintainer on March 31, 2026, and added to the GitHub Advisory Database on April 1, 2026. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, phpMyFAQ Advisory).

Technical details

The root cause is a regex-based sanitizer bypass (CWE-79) in phpmyfaq/src/phpMyFAQ/Helper/SvgSanitizer.php. The regex /href\s*=\s*["']javascript:[^"']*["']/i detects literal javascript: strings but fails to match HTML entity-encoded variants such as &#106;avascript:, which browsers decode and execute normally. Additionally, the DANGEROUS_ELEMENTS blocklist omits certain SVG elements (e.g., <script>, <use>, <animate>) that can also trigger JavaScript execution. Uploaded SVGs are served with Content-Type: image/svg+xml and no Content-Disposition: attachment header, causing browsers to render them inline. The vulnerable upload endpoint (/admin/api/content/images) requires only the edit_faq permission, not full admin rights (GitHub Advisory, phpMyFAQ Advisory).

Impact

Successful exploitation enables a low-privileged editor to escalate privileges to full administrator by tricking an admin into viewing a malicious SVG. The injected JavaScript executes in the admin's browser within the phpMyFAQ origin, allowing the attacker to create backdoor admin accounts via the admin API, exfiltrate sensitive configuration data (database credentials, API tokens), and modify or delete FAQ content. The scope change (from editor to admin) means the impact extends beyond the attacker's own session to the entire phpMyFAQ installation (GitHub Advisory).

Exploitability

A detailed proof-of-concept (PoC) is publicly available in the official security advisory, including step-by-step instructions for both basic XSS (confirmed in Chrome 146 and Edge) and full privilege escalation to admin takeover (phpMyFAQ Advisory). Exploitation requires a low-privilege account with edit_faq permission and user interaction (an admin must open the malicious SVG URL). The EPSS score is approximately 0.029–0.041%, indicating a low but non-negligible probability of exploitation in the wild. There is no current evidence of active in-the-wild exploitation or CISA KEV catalog listing (GitHub Advisory).

Exploitation steps

  1. Obtain editor access: Log in to the phpMyFAQ admin panel with any account that has the edit_faq permission (editor role).
  2. Navigate to FAQ creation: Go to Admin → Content → Add New FAQ and open the TinyMCE editor.
  3. Craft malicious SVG: Create an SVG file containing an <a> element with an HTML entity-encoded javascript: URL in the href attribute (e.g., <a href="&#106;avascript:alert(document.domain)">Click for XSS</a>), bypassing the regex sanitizer.
  4. Upload the SVG: Click the image upload button in TinyMCE and upload the crafted SVG. The file is stored at /content/user/images/<filename>.svg.
  5. Deliver the payload: For privilege escalation, craft the SVG payload to call the phpMyFAQ admin API to create a backdoor admin account (e.g., backdoor:H4ck3d!) when clicked. Send the SVG URL to a target admin via social engineering (e.g., disguised as a system notice).
  6. Admin triggers execution: The admin opens the SVG URL in their browser and clicks the link. JavaScript executes in their browser session on the phpMyFAQ origin.
  7. Achieve admin takeover: The script silently creates a backdoor admin account. The attacker logs in with the new credentials and has full administrative access (phpMyFAQ Advisory).

Indicators of compromise

  • Network: Unexpected POST requests to /admin/api/content/images uploading SVG files from editor-level accounts; outbound requests from admin browsers to external attacker-controlled infrastructure after viewing SVG files.
  • File System: SVG files in /content/user/images/ containing HTML entity-encoded javascript: strings (e.g., &#106;avascript:, &#x6A;avascript:) or suspicious SVG elements (<script>, <use>, <animate>).
  • Logs: Web server access logs showing admin-level users accessing SVG file URLs directly (not embedded in FAQ pages); admin API calls to create new user accounts (/admin/api/user) immediately following SVG file access.
  • Application: Unexpected new admin accounts created in phpMyFAQ (e.g., accounts with names like backdoor) with no corresponding legitimate administrative action in audit logs (phpMyFAQ Advisory).

Mitigation and workarounds

Update phpMyFAQ to version 4.1.1 or later, which addresses this vulnerability (phpMyFAQ Release). As interim workarounds: restrict the edit_faq permission to fully trusted users only; configure the web server to serve SVG files with Content-Disposition: attachment to prevent inline browser rendering; and implement a Content Security Policy (CSP) header that restricts script execution. The advisory also recommends replacing the regex-based sanitizer with a DOM-based allowlist approach for long-term robustness (GitHub Advisory, phpMyFAQ Advisory).

Community reactions

The vulnerability was reported by security researcher 0xmanhnv and disclosed responsibly through GitHub's security advisory process. The maintainer (thorsten) published the advisory and released the patch (v4.1.1) on March 31, 2026. No significant broader media coverage or notable community commentary beyond the advisory itself has been identified at this time (phpMyFAQ Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management