CVE-2026-48488 – phpMyFAQ has Weak Cryptography – SHA1 for Password Hashing

CVE ID :CVE-2026-48488

Published : June 8, 2026, 4:16 p.m. | 17 minutes ago

Description :phpMyFAQ is an open source FAQ web application. Prior to version 4.1.4, attachment passwords are hashed using SHA-1, a cryptographically broken algorithm. SHA-1 has been vulnerable to collision attacks since 2017 (SHAttered). Version 4.1.4 fixes the issue.

Severity: 2.7 | LOW

Visit the link for more details, such as CVSS details, affected products, timeline, and more… 

نوشته های مشابه