CVE-2026-48488 – phpMyFAQ has Weak Cryptography – SHA1 for Password Hashing
CVE ID :CVE-2026-48488
Published : June 8, 2026, 4:16 p.m. | 17 minutes ago
Description :phpMyFAQ is an open source FAQ web application. Prior to version 4.1.4, attachment passwords are hashed using SHA-1, a cryptographically broken algorithm. SHA-1 has been vulnerable to collision attacks since 2017 (SHAttered). Version 4.1.4 fixes the issue.
Severity: 2.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more…