CVE-2026-48488
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Jun 08, 2026
Vendor
unknown
Description
phpMyFAQ is an open source FAQ web application. Prior to version 4.1.4, attachment passwords are hashed using SHA-1, a cryptographically broken algorithm. SHA-1 has been vulnerable to collision attacks since 2017 (SHAttered). Version 4.1.4 fixes the issue.