FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-04-28 14:09:37 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
ddd3fcc9-2bdd-11ee-9af4-589cfc0f81b0phpmyfaq -- multiple vulnerabilities

phpmyfaq developers report:

Cross Site Scripting vulnerability

CSV injection vulnerability


Discovery 2023-07-16
Entry 2023-08-23
phpmyfaq-php80
phpmyfaq-php81
phpmyfaq-php82
phpmyfaq-php83
< 3.1.16

https://huntr.dev/bounties/e891dcbc-2092-49d3-9518-23e37187a5ea/
https://huntr.dev/bounties/36149a42-cbd5-445e-a371-e351c899b189/
4f370c80-79ce-11ee-be8e-589cfc0f81b0phpmyfaq -- multiple vulnerabilities

phpmyfaq developers report:

XSS

Insufficient session expiration


Discovery 2023-10-31
Entry 2023-11-02
phpmyfaq-php80
phpmyfaq-php81
phpmyfaq-php82
phpmyfaq-php83
< 3.2.2

CVE-2023-5863
CVE-2023-5865
https://nvd.nist.gov/vuln/detail/CVE-2023-5863
https://nvd.nist.gov/vuln/detail/CVE-2023-5865
https://huntr.com/bounties/fbfd4e84-61fb-4063-8f11-15877b8c1f6f/
https://huntr.com/bounties/4c4b7395-d9fd-4ca0-98d7-2e20c1249aff/
cbfc1591-c8c0-11ee-b45a-589cfc0f81b0phpmyfaq -- multiple vulnerabilities

phpMyFAQ team reports:

phpMyFAQ doesn't implement sufficient checks to avoid XSS when storing on attachments filenames. The 'sharing FAQ' functionality allows any unauthenticated actor to misuse the phpMyFAQ application to send arbitrary emails to a large range of targets. phpMyFAQ's user removal page allows an attacker to spoof another user's detail, and in turn make a compelling phishing case for removing another user's account.


Discovery 2024-02-05
Entry 2024-02-11
phpmyfaq-php81
phpmyfaq-php82
phpmyfaq-php83
< 3.2.5

https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-7m8g-fprr-47fx
https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-9hhf-xmcw-r3xg
https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-6648-6g96-mg35
8b3be705-eba7-11ee-99b3-589cfc0f81b0phpmyfaq -- multiple vulnerabilities

phpMyFAQ team reports:

The phpMyFAQ Team has learned of multiple security issues that'd been discovered in phpMyFAQ 3.2.5 and earlier. phpMyFAQ contains cross-site scripting (XSS), SQL injection and bypass vulnerabilities.


Discovery 2024-03-25
Entry 2024-03-26
phpmyfaq-php81
phpmyfaq-php82
phpmyfaq-php83
< 3.2.6

https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-mmh6-5cpf-2c72
https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-hm8r-95g3-5hj9
https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-48vw-jpf8-hwqh
https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-2grw-mc9r-822r
https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-6p68-36m6-392r
https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-pwh2-fpfr-x5gf
https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-q7g6-xfh2-vhpx
https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-qgxx-4xv5-6hcw