CVE-2026-85586

phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA protection and submit unlimited questions directly, causing database pollution and triggering outgoing mail notifications.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-04 12:17

Updated : 2026-09-10 16:17


NVD link : CVE-2026-85586

Mitre link : CVE-2026-85586

CVE.ORG link : CVE-2026-85586


JSON object : View

Products Affected

No product.

CWE
CWE-799

Improper Control of Interaction Frequency