
CVE-2026-34729 phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, there is a stored XSS vulnerability via Regex Bypass in Filter::removeAttributes(). This issue… https://www.cve.org/CVERecord?id=CVE-2026-34729
Post summary
The post announces a stored XSS vulnerability in phpMyFAQ (pre‑4.1.1) caused by a regex bypass in the removeAttributes method, with no evidence of exploitation, patches, or PoC.
