Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-85586

Опубликовано: 04 сент. 2026
Источник: nvd
EPSS Низкий

Описание

phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA protection and submit unlimited questions directly, causing database pollution and triggering outgoing mail notifications.

EPSS

Процентиль: 29%
0.00359
Низкий

Дефекты

CWE-799

Связанные уязвимости

github
14 дней назад

phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA protection and submit unlimited questions directly, causing database pollution and triggering outgoing mail notifications.

CVSS3: 5.3
fstec
29 дней назад

Уязвимость веб-приложения phpMyFAQ, связанная с недостаточным контролем за частотой взаимодействий, позволяющая нарушителю обойти существующие механизмы безопасности

EPSS

Процентиль: 29%
0.00359
Низкий

Дефекты

CWE-799