phpMyFAQ is an open source FAQ web application. Versions 4.0.16 and below allow an authenticated user without the dlattachment permission to download FAQ attachments due to a incomprehensive permissions check. The presence of a right key is improperly validated as proof of authorization in attachment.php. Additionally, the group and user permission logic contains a flawed conditional expression that may allow unauthorized access. This issue has been fixed in version
We have discovered 213 live websites that are affected by CVE-2026-24420.
| Product | |
| Category | Miscellaneous |
| Vulnerable Domains | 213 live websites (100% of phpMyFAQ install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 43 versions ( 100% of all versions) |
| 41 websites | |
| 91 websites | |
| 11 websites | |
| 10 websites | |
| 6 websites | |
| 6 websites | |
| 5 websites | |
| 3 websites | |
| 3 websites | |
| 3 websites |
| .com | 59 websites |
| .de | 58 websites |
| .net | 14 websites |
| .org | 9 websites |
| .nl | 6 websites |
| .fr | 5 websites |
| .info | 5 websites |
| .com.br | 4 websites |
| .ch | 3 websites |
| .jp | 3 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***.*************.de | **,*** | ||
| ***.********.de | ***,*** | ||
| *************.org | ***,*** | ||
| ****.**********.com | ***,*** | ||
| ***.*******.**.th | ***,*** | ||
| ***.*******.com | ***,*** | ||
| ***.****.de | ***,*** | ||
| ***.***************.de | ***,*** | ||
| *********.com | *,***,*** | ||
| ***.******.com | *,***,*** |
FAQ