CVE-2025-69200General(phpmyfaq / phpmyfaq)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch phpmyfaq phpmyfaq systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

phpMyFAQ is an open source FAQ web application. In versions prior to 4.0.16, an unauthenticated remote attacker can trigger generation of a configuration backup ZIP via `POST /api/setup/backup` and then download the generated ZIP from a web-accessible location. The ZIP contains sensitive configuration files (e.g., `database.php` with database credentials), leading to high-impact information disclosure and potential follow-on compromise. Version 4.0.16 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-202

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • phpmyfaq

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • General: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-02-11)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
phpmyfaq

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-10: 1Mentions · 2026-02-11: 2Patch / Workaround · 2026-02-10: 102-1002-11
Signal classification2 categories
General
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-101
Patch1
2026-02-112
General2
Full discourse3 posts
  • Cloud Virtues@CloudVirtues
    General

    CVE-2025-69200 - phpMyFAQ vulnerability https://dy.si/umxK8 https://t.co/iEk90ropoc

    Post summary

    The tweet references CVE-2025-69200 affecting phpMyFAQ and includes two URLs, but provides no additional technical or exploitation details.

    0002044
    12 followersView on X
  • Threat Intelligence@threatintel
    Patch

    #ThreatProtection #CVE-2025-69200 - #phpMyFAQ #vulnerability, read more about Symantec's protection: https://www.broadcom.com/support/security-center/protection-bulletin/cve-2025-69200-phpmyfaq-vulnerability

    Post summary

    The tweet directs readers to a Symantec protection bulletin for CVE‑2025‑69200 in phpMyFAQ, indicating a vendor patch or mitigation is available, but provides no PoC or exploitation details.

    01010803
    114.2K followersView on X
  • Dr. Siraj Dokadia@SirajD_Official
    General

    CVE-2025-69200 - phpMyFAQ vulnerability https://dy.si/MDzH7s https://t.co/BDZuUju2P5

    Post summary

    The tweet merely announces CVE-2025-69200 as a phpMyFAQ vulnerability, linking to external URLs, but provides no further technical or operational details.

    0000039
    14 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appphpmyfaqphpmyfaq---
Appphpmyfaqphpmyfaq4.1.0--

Explore more