<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T23:21:44.569939+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329550</id>
    <title>EUVD-2026-329550</title>
    <updated>2026-10-05T23:21:44.616829+00:00</updated>
    <content>EUVD-2026-329550</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329550"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35675</id>
    <title>fkie_cve-2026-35675</title>
    <updated>2026-10-05T23:21:44.616867+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthenticated attackers to reset any user account password without token verification or email confirmation. Attackers can enumerate valid usernames, obtain plaintext passwords via email, and achieve complete account takeover including administrative access.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-35675"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w9xh-5f39-vq89</id>
    <title>GHSA-w9xh-5f39-vq89 — phpMyFAQ: Missing Password Reset Token Allows Account Takeover via Username/Email Enumeration</title>
    <updated>2026-10-05T23:21:44.616901+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: thorsten/phpmyfaq, Packagist: phpmyfaq/phpmyfaq</p>
<p>### Summary
An authentication bypass vulnerability in phpMyFAQ allows any unauthenticated attacker to reset the password of any user account, including SuperAdmin accounts. By sending a PUT request with just a valid username and associated email address to /api/user/password/update, an attacker receives a new plaintext password via email without any token verification, rate limiting, or email confirmation. This enables complete account takeover of any user, including full administrative access.</p>
<p>### Details
File: phpmyfaq/src/phpMyFAQ/Controller/Frontend/Api/UnauthorizedUserController.php
Lines: 56-130
The updatePassword() method at line 56 accepts PUT requests to /user/password/update with only username and email in the JSON body:
#[Route(path: 'user/password/update', name: 'api.private.user.password', methods: ['PUT'])]
```php
public function updatePassword(Request $request): JsonResponse
{
    $data = json_decode($request-&gt;getContent());
    $username = trim((string) Filter::filterVar($data-&gt;username, FILTER_SANITIZE_SPECIAL_CHARS));
    $email = trim((string) Filter::filterEmail($data-&gt;email));
    if ($username !== '' &amp;&amp; $username !== '0' &amp;&amp; ($email !== '' &amp;&amp; $email !== '0')) {
        $user = ($this-&gt;currentUserFactory ?? CurrentUser::getCurrentUser(...))($this-&gt;configuration);
        $loginExist = $user-&gt;getUserByLogin($username);
        if ($loginExist &amp;&amp; $email === $user-&gt;getUserData('email')) {
            // NO TOKEN CHECK
            // NO RATE LIMITING…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w9xh-5f39-vq89"/>
  </entry>
</feed>
