CVE-2026-76212

Source
https://cve.org/CVERecord?id=CVE-2026-76212
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-76212.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-76212
Aliases
  • GHSA-5hx6-c293-588h
Published
2026-08-19T14:01:58Z
Modified
2026-09-03T03:48:20Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
phpMyFAQ before 4.1.7 LIKE Wildcard Injection via PostgreSQL
Details

phpMyFAQ before 4.1.7, when configured to use PostgreSQL via the native pgsql PHP extension, declares an incorrect LIKE ESCAPE character ('=') in the Search/Database/Pgsql.php backend while escapeLikeWildcards() escapes user input with the '|' prefix. As a result, wildcard escaping is a no-op and user-supplied % and _ characters remain active LIKE wildcards. An unauthenticated attacker can submit such characters in the public FAQ search form to force maximally broad pattern matches and expensive sequential scans, resulting in a denial of service. The PDO PostgreSQL backend is not affected, and quotes remain escaped so this does not enable quote-breaking SQL injection or data exfiltration.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-88"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76212.json"
}
References

Affected packages

Git / github.com/thorsten/phpmyfaq

Affected ranges

Type
GIT
Repo
https://github.com/thorsten/phpmyfaq
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:phpmyfaq:phpmyfaq:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "4.2.0-alpha"
        },
        {
            "fixed": "4.1.7"
        },
        {
            "introduced": "0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-76212.json"