
🚨 Critical - Multiple phpMyFAQ Vulnerabilities (CVE-2026-46364, CVE-2026-45010) phpMyFAQ contains critical vulnerabilities that may allow unauthenticated attackers to perform SQL injection through crafted User-Agent headers and brute-force TOTP authentication codes via the /admin/check endpoint. Successful exploitation could lead to credential disclosure and full administrative account takeover. 👉 Affected: phpMyFAQ < 4.1.2 | Fix: Upgrade to 4.1.2
Post summary
phpMyFAQ versions below 4.1.2 contain critical SQL injection and TOTP brute‑force flaws that allow credential theft and full admin takeover; upgrading to 4.1.2 addresses the issue.

