OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-56738

HIGH · CVSS 8.5 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The `StopWords::add()` method in phpMyFAQ versions prior to 4.1.6 is vulnerable to SQL injection due to improper handling of user-supplied input, allowing authenticated administrators to execute arbitrary SQL commands. This vulnerability can lead to severe impacts, including data exfiltration, table deletion, or unauthorized modifications within the database. Organizations using phpMyFAQ should prioritize upgrading to version 4.1.6 or later to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-56738
Severity
HIGH
CVSS
8.5
EPSS
0.26%

Original NVD Description

phpMyFAQ is an open source FAQ web application. The `StopWords::add()` method inversions prior to 4.1.6 builds a SQL `INSERT` statement using `sprintf()` and inserts the user-supplied stop word value directly into the query string without calling the application's database escaping function on it. A sibling method, `StopWords::update()`, which modifies an existing stop word, correctly escapes the same kind of input. The omission is isolated to the `add()` (insert) code path. An authenticated administrator who can reach the stop-word management feature can submit a crafted value as the "word" parameter that breaks out of the SQL string literal and injects arbitrary SQL, including statements to drop tables, exfiltrate data, or modify other rows in the database. Version 4.1.6 fixes the issue.