SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-75920

MEDIUM · CVSS 5.3 EPSS 0.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

phpMyFAQ versions prior to 4.1.6 are vulnerable due to the insecure handling of backup ZIP archives, which are stored in the web-accessible document root, allowing exposure of sensitive files such as database credentials. Unauthenticated attackers can exploit this vulnerability by racing concurrent requests to download the backup file before it is deleted, or by leveraging XSS in admin contexts to trigger and access the backup. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access to sensitive information.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75920
Severity
MEDIUM
CVSS
5.3
EPSS
0.33%

Original NVD Description

phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at content.zip, exposing sensitive files including database credentials. Unauthenticated attackers can race concurrent requests to download the temporary ZIP file before deletion, or exploit XSS in admin contexts to trigger authenticated backups and retrieve the archive.

Related CVEs

Other vulnerabilities affecting the same vendor(s)