<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 19:19:28 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-329550</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329550</link>
      <description>EUVD-2026-329550</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329550</guid>
    </item>
    <item>
      <title>fkie_cve-2026-35675</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35675</link>
      <description>&lt;p&gt;phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthenticated attackers to reset any user account password without token verification or email confirmation. Attackers can enumerate valid usernames, obtain plaintext passwords via email, and achieve complete account takeover including administrative access.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthenticated attackers to reset any user account password without token verification or email confirmation. Attackers can enumerate valid usernames, obtain plaintext passwords via email, and achieve complete account takeover including administrative access.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-35675</guid>
    </item>
    <item>
      <title>GHSA-w9xh-5f39-vq89 — phpMyFAQ: Missing Password Reset Token Allows Account Takeover via Username/Email Enumeration</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w9xh-5f39-vq89</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: thorsten/phpmyfaq, Packagist: phpmyfaq/phpmyfaq&lt;/p&gt;
&lt;p&gt;### Summary
An authentication bypass vulnerability in phpMyFAQ allows any unauthenticated attacker to reset the password of any user account, including SuperAdmin accounts. By sending a PUT request with just a valid username and associated email address to /api/user/password/update, an attacker receives a new plaintext password via email without any token verification, rate limiting, or email confirmation. This enables complete account takeover of any user, including full administrative access.&lt;/p&gt;
&lt;p&gt;### Details
File: phpmyfaq/src/phpMyFAQ/Controller/Frontend/Api/UnauthorizedUserController.php
Lines: 56-130
The updatePassword() method at line 56 accepts PUT requests to /user/password/update with only username and email in the JSON body:
#[Route(path: &amp;#39;user/password/update&amp;#39;, name: &amp;#39;api.private.user.password&amp;#39;, methods: [&amp;#39;PUT&amp;#39;])]
```php
public function updatePassword(Request $request): JsonResponse
{
    $data = json_decode($request-&amp;gt;getContent());
    $username = trim((string) Filter::filterVar($data-&amp;gt;username, FILTER_SANITIZE_SPECIAL_CHARS));
    $email = trim((string) Filter::filterEmail($data-&amp;gt;email));
    if ($username !== &amp;#39;&amp;#39; &amp;amp;&amp;amp; $username !== &amp;#39;0&amp;#39; &amp;amp;&amp;amp; ($email !== &amp;#39;&amp;#39; &amp;amp;&amp;amp; $email !== &amp;#39;0&amp;#39;)) {
        $user = ($this-&amp;gt;currentUserFactory ?? CurrentUser::getCurrentUser(...))($this-&amp;gt;configuration);
        $loginExist = $user-&amp;gt;getUserByLogin($username);
        if ($loginExist &amp;amp;&amp;amp; $email === $user-&amp;gt;getUserData(&amp;#39;email&amp;#39;)) {
            // NO TOKEN CHECK
            // NO RATE LIMITING…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: thorsten/phpmyfaq, Packagist: phpmyfaq/phpmyfaq&lt;/p&gt;
&lt;p&gt;### Summary
An authentication bypass vulnerability in phpMyFAQ allows any unauthenticated attacker to reset the password of any user account, including SuperAdmin accounts. By sending a PUT request with just a valid username and associated email address to /api/user/password/update, an attacker receives a new plaintext password via email without any token verification, rate limiting, or email confirmation. This enables complete account takeover of any user, including full administrative access.&lt;/p&gt;
&lt;p&gt;### Details
File: phpmyfaq/src/phpMyFAQ/Controller/Frontend/Api/UnauthorizedUserController.php
Lines: 56-130
The updatePassword() method at line 56 accepts PUT requests to /user/password/update with only username and email in the JSON body:
#[Route(path: &amp;#39;user/password/update&amp;#39;, name: &amp;#39;api.private.user.password&amp;#39;, methods: [&amp;#39;PUT&amp;#39;])]
```php
public function updatePassword(Request $request): JsonResponse
{
    $data = json_decode($request-&amp;gt;getContent());
    $username = trim((string) Filter::filterVar($data-&amp;gt;username, FILTER_SANITIZE_SPECIAL_CHARS));
    $email = trim((string) Filter::filterEmail($data-&amp;gt;email));
    if ($username !== &amp;#39;&amp;#39; &amp;amp;&amp;amp; $username !== &amp;#39;0&amp;#39; &amp;amp;&amp;amp; ($email !== &amp;#39;&amp;#39; &amp;amp;&amp;amp; $email !== &amp;#39;0&amp;#39;)) {
        $user = ($this-&amp;gt;currentUserFactory ?? CurrentUser::getCurrentUser(...))($this-&amp;gt;configuration);
        $loginExist = $user-&amp;gt;getUserByLogin($username);
        if ($loginExist &amp;amp;&amp;amp; $email === $user-&amp;gt;getUserData(&amp;#39;email&amp;#39;)) {
            // NO TOKEN CHECK
            // NO RATE LIMITING…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w9xh-5f39-vq89</guid>
    </item>
  </channel>
</rss>
