A vulnerability, which was classified as problematic, has been found in thorsten phpMyFAQ up to 4.1.1. Affected is the function
Utils::parseUrl of the component FAQ Page. The manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2026-46367. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.