CVE-2026-75920

phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at content.zip, exposing sensitive files including database credentials. Unauthenticated attackers can race concurrent requests to download the temporary ZIP file before deletion, or exploit XSS in admin contexts to trigger authenticated backups and retrieve the archive.

Scoring

Severity
MEDIUM
CVSS base score
6
CVSS vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS probability
0.33%
CWE
CWE-377
Published
2026-08-19
Last modified
2026-08-20

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs