Vulnerabilities in thorsten

118 results
Vexday analysis

Com 115 CVEs catalogadas e 24 surgidas nos últimos 90 dias, o vendor Thorsten apresenta um volume de vulnerabilidades recente que merece atenção contínua. A taxa de exploração ativa está abaixo da média geral do catálogo, com nenhuma entrada no CISA KEV, o que sugere menor pressão imediata de ataques em curso — embora 7 falhas de severidade crítica e 4 com PoC pública representem superfície de ataque concreta. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), indicando lacunas persistentes em validação e sanitização de entrada. A CVE mais perigosa no momento, CVE-2022-3766, registra EPSS de 0.0574, valor relativamente contido, mas que deve ser monitorado especialmente em ambientes onde atualizações não são aplicadas de forma sistemática.

CVE-2025-62519HIGHphpMyFAQ has Authenticated SQL Injection in Configuration Update FunctionalityEPSS 0.8%CVE-2024-22208MEDIUMphpMyFAQ sharing FAQ functionality can easily be abused for phishing purposesEPSS 0.7%CVE-2023-1753MEDIUMWeak Password Requirements in thorsten/phpmyfaqEPSS 0.7%CVE-2023-0790HIGHUncaught Exception in thorsten/phpmyfaqEPSS 0.7%CVE-2023-0793HIGHWeak Password Requirements in thorsten/phpmyfaqEPSS 0.7%CVE-2023-1887HIGHBusiness Logic Errors in thorsten/phpmyfaqEPSS 0.7%CVE-2026-34728HIGHphpMyFAQ: Path Traversal - Arbitrary File Deletion in MediaBrowserControllerEPSS 0.7%CVE-2024-27300MEDIUMphpMyFAQ Stored XSS at user emailEPSS 0.7%CVE-2023-0307MEDIUMWeak Password Requirements in thorsten/phpmyfaqEPSS 0.6%CVE-2023-0792MEDIUM Code Injection in thorsten/phpmyfaqEPSS 0.6%CVE-2023-1755HIGHCross-site Scripting (XSS) - Generic in thorsten/phpmyfaqEPSS 0.6%CVE-2023-0880HIGHMisinterpretation of Input in thorsten/phpmyfaqEPSS 0.6%CVE-2023-1754MEDIUMImproper Neutralization of Input During Web Page Generation in thorsten/phpmyfaqEPSS 0.6%CVE-2023-0786HIGHCross-site Scripting (XSS) - Generic in thorsten/phpmyfaqEPSS 0.6%CVE-2024-22202MEDIUMUser Removal Page Allows Spoofing Of User DetailsEPSS 0.6%CVE-2024-29196LOWphpMyFAQ Path Traversal in AttachmentsEPSS 0.6%CVE-2023-5865HIGHInsufficient Session Expiration in thorsten/phpmyfaqEPSS 0.6%CVE-2023-3469MEDIUMCross-site Scripting (XSS) - Reflected in thorsten/phpmyfaqEPSS 0.6%CVE-2023-0312HIGHCross-site Scripting (XSS) - Stored in thorsten/phpmyfaqEPSS 0.6%CVE-2023-2428MEDIUMCross-site Scripting (XSS) - Stored in thorsten/phpmyfaqEPSS 0.6%