
⚠️⚠️ CVE-2026-46364 (CVSS 9.8): Unauthenticated SQL injection via malicious User-Agent on /api/captcha 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJwaHBNeUZBUSI%3D 🎯1.2K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="phpMyFAQ" 🔖Refer: https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-289f-fq7w-6q2w #OSINT #FOFA #CyberSecurity #Vulnerability
Post summary
A disclosure of CVE-2026-46364, an unauthenticated SQL injection in phpMyFAQ, is presented along with FOFA search results and a vendor advisory link indicating a fix is available.




