
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34974 is a Stored Cross-Site Scripting (XSS) vulnerability in phpMyFAQ's SVG sanitizer (SvgSanitizer.php) that allows privilege escalation from editor to full administrator. The flaw affects all phpMyFAQ versions up to and including 4.1.0, and was introduced with the SvgSanitizer class on 2026-01-15. It was published by the maintainer on March 31, 2026, and added to the GitHub Advisory Database on April 1, 2026. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, phpMyFAQ Advisory).
The root cause is a regex-based sanitizer bypass (CWE-79) in phpmyfaq/src/phpMyFAQ/Helper/SvgSanitizer.php. The regex /href\s*=\s*["']javascript:[^"']*["']/i detects literal javascript: strings but fails to match HTML entity-encoded variants such as javascript:, which browsers decode and execute normally. Additionally, the DANGEROUS_ELEMENTS blocklist omits certain SVG elements (e.g., <script>, <use>, <animate>) that can also trigger JavaScript execution. Uploaded SVGs are served with Content-Type: image/svg+xml and no Content-Disposition: attachment header, causing browsers to render them inline. The vulnerable upload endpoint (/admin/api/content/images) requires only the edit_faq permission, not full admin rights (GitHub Advisory, phpMyFAQ Advisory).
Successful exploitation enables a low-privileged editor to escalate privileges to full administrator by tricking an admin into viewing a malicious SVG. The injected JavaScript executes in the admin's browser within the phpMyFAQ origin, allowing the attacker to create backdoor admin accounts via the admin API, exfiltrate sensitive configuration data (database credentials, API tokens), and modify or delete FAQ content. The scope change (from editor to admin) means the impact extends beyond the attacker's own session to the entire phpMyFAQ installation (GitHub Advisory).
A detailed proof-of-concept (PoC) is publicly available in the official security advisory, including step-by-step instructions for both basic XSS (confirmed in Chrome 146 and Edge) and full privilege escalation to admin takeover (phpMyFAQ Advisory). Exploitation requires a low-privilege account with edit_faq permission and user interaction (an admin must open the malicious SVG URL). The EPSS score is approximately 0.029–0.041%, indicating a low but non-negligible probability of exploitation in the wild. There is no current evidence of active in-the-wild exploitation or CISA KEV catalog listing (GitHub Advisory).
edit_faq permission (editor role).<a> element with an HTML entity-encoded javascript: URL in the href attribute (e.g., <a href="javascript:alert(document.domain)">Click for XSS</a>), bypassing the regex sanitizer./content/user/images/<filename>.svg.backdoor:H4ck3d!) when clicked. Send the SVG URL to a target admin via social engineering (e.g., disguised as a system notice)./admin/api/content/images uploading SVG files from editor-level accounts; outbound requests from admin browsers to external attacker-controlled infrastructure after viewing SVG files./content/user/images/ containing HTML entity-encoded javascript: strings (e.g., javascript:, javascript:) or suspicious SVG elements (<script>, <use>, <animate>)./admin/api/user) immediately following SVG file access.backdoor) with no corresponding legitimate administrative action in audit logs (phpMyFAQ Advisory).Update phpMyFAQ to version 4.1.1 or later, which addresses this vulnerability (phpMyFAQ Release). As interim workarounds: restrict the edit_faq permission to fully trusted users only; configure the web server to serve SVG files with Content-Disposition: attachment to prevent inline browser rendering; and implement a Content Security Policy (CSP) header that restricts script execution. The advisory also recommends replacing the regex-based sanitizer with a DOM-based allowlist approach for long-term robustness (GitHub Advisory, phpMyFAQ Advisory).
The vulnerability was reported by security researcher 0xmanhnv and disclosed responsibly through GitHub's security advisory process. The maintainer (thorsten) published the advisory and released the patch (v4.1.1) on March 31, 2026. No significant broader media coverage or notable community commentary beyond the advisory itself has been identified at this time (phpMyFAQ Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."