phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA protection and submit unlimited questions directly, causing database pollution and triggering outgoing mail notifications.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-04 12:17
Updated : 2026-09-10 16:17
NVD link : CVE-2026-85586
Mitre link : CVE-2026-85586
CVE.ORG link : CVE-2026-85586
JSON object : View
Products Affected
No product.
CWE
CWE-799
Improper Control of Interaction Frequency
