{"id":"CVE-2026-57994","summary":"phpMyFAQ - Information Disclosure of Inactive FAQ Content via Public API Endpoints","details":"phpMyFAQ before 4.1.5 applies inconsistent active=yes and publication-date filtering across its public FAQ API endpoints, allowing unauthenticated attackers to retrieve inactive (draft or review-only) FAQ content. Specifically, GET /api/v3.1/faq/{categoryId}/{faqId} returns the inactive FAQ title and full answer, while GET /api/v3.1/faqs/tags/{tagId} and GET /api/v4.0/faqs/tags/{tagId} return the inactive FAQ title and answer preview, disclosing non-public content.","aliases":["GHSA-mf8r-wm2w-f8c5"],"modified":"2026-08-12T03:51:08.711537345Z","published":"2026-07-10T13:58:00.962Z","database_specific":{"cwe_ids":["CWE-200"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57994.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57994.json"},{"type":"ADVISORY","url":"https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-mf8r-wm2w-f8c5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57994"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/phpmyfaq-information-disclosure-of-inactive-faq-content-via-public-api-endpoints"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/thorsten/phpmyfaq","events":[{"introduced":"104a42f33cdcb85c3be9b30cd50e3bce3d51ada3"},{"fixed":"aea44f5f3568f1d4659a07bad3f59b41260d1b88"}],"database_specific":{"source":["AFFECTED_FIELD","DESCRIPTION"],"extracted_events":[{"introduced":"4.1.0"},{"fixed":"4.1.5"},{"introduced":"0"}]}}],"versions":["4.1.4","4.1.3","4.1.2","4.1.1","4.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-57994.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}