PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Web Vulnerabilities·Updated Jun 11, 2026

phpMyFAQ <= 4.1.1 - SQL Injection

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-46364
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector() and BuiltinCaptcha::saveCaptcha() methods that interpolate unsanitized User-Agent headers into DELETE and INSERT queries. Unauthenticated attackers can exploit the public GET /api/captcha endpoint by crafting malicious User-Agent headers to perform time-based blind SQL injection, extracting sensitive data including user credentials, admin tokens, and SMTP credentials from the database.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
phpmyfaqby thorsten
AFFECTED< 4.1.2SAFE ✓≥ 4.1.2
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

phpMyFAQ <= 4.1.1 - SQL Injection Scanner | S4E