phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthenticated attackers to reset any user account password without token verification or email confirmation. Attackers can enumerate valid usernames, obtain plaintext passwords via email, and achieve complete account takeover including administrative access.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-w9xh-5f39-vq89 | phpMyFAQ: Missing Password Reset Token Allows Account Takeover via Username/Email Enumeration |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 28 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthenticated attackers to reset any user account password without token verification or email confirmation. Attackers can enumerate valid usernames, obtain plaintext passwords via email, and achieve complete account takeover including administrative access. | |
| Title | phpMyFAQ - Authentication Bypass via Missing Password Reset Token in /api/user/password/update | |
| First Time appeared |
Phpmyfaq
Phpmyfaq phpmyfaq |
|
| Weaknesses | CWE-307 | |
| CPEs | cpe:2.3:a:phpmyfaq:phpmyfaq:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Phpmyfaq
Phpmyfaq phpmyfaq |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-28T14:15:19.113Z
Reserved: 2026-04-04T12:32:50.477Z
Link: CVE-2026-35675
No data.
Status : Received
Published: 2026-05-28T16:16:21.800
Modified: 2026-05-28T16:16:21.800
Link: CVE-2026-35675
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA