
CVE-2026-34974 phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the regex-based SVG sanitizer in phpMyFAQ (SvgSanitizer.php) can be bypassed using HTML entity encoding in javascript https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34974
Post summary
The note discloses a bypassable SVG sanitizer flaw in phpMyFAQ (v4.1.1‑earlier) using HTML‑entity‑encoded JavaScript; no patch, PoC, or evidence of active exploitation is provided.

