phpMyFAQ is an open source FAQ web application. Prior to version 4.1.4, attachment passwords are hashed using SHA-1, a cryptographically broken algorithm. SHA-1 has been vulnerable to collision attacks since 2017 (SHAttered). Version 4.1.4 fixes the issue.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 08 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | phpMyFAQ is an open source FAQ web application. Prior to version 4.1.4, attachment passwords are hashed using SHA-1, a cryptographically broken algorithm. SHA-1 has been vulnerable to collision attacks since 2017 (SHAttered). Version 4.1.4 fixes the issue. | |
| Title | phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing | |
| Weaknesses | CWE-328 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-08T15:15:12.595Z
Reserved: 2026-05-21T15:33:08.291Z
Link: CVE-2026-48488
No data.
Status : Received
Published: 2026-06-08T16:16:43.227
Modified: 2026-06-08T16:16:43.227
Link: CVE-2026-48488
No data.
OpenCVE Enrichment
No data.
Weaknesses