A vulnerability, which was classified as problematic, has been found in thorsten phpMyFAQ up to 4.1.1. Affected is the function Utils::parseUrl of the component FAQ Page. The manipulation leads to cross site scripting.

This vulnerability is listed as CVE-2026-46367. The attack may be initiated remotely. There is no available exploit.

It is advisable to upgrade the affected component.