[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2025-59943":6},{"stargazers_count":4,"fetched_at":5},5,"2026-04-18T20:14:10.345Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":100,"aliases":110,"duplicate_of":9,"upstream":111,"downstream":112,"duplicates":113,"related":114,"reserved_at":9,"published_at":115,"modified_at":116,"state":117,"summary":118,"references_raw":126,"kevs":141,"epss":142,"epss_history":145,"metrics":417,"affected":429},"CVE-2025-59943","phpMyFAQ is an open source FAQ web application. Versions 4.0-nightly-2025-10-03 and below do not enforce uniqueness of email addresses during user registration. This allows multiple distinct accounts to be created with the same email. Because email is often used as an identifier for password resets, notifications, and administrative actions, this flaw can cause account ambiguity and, in certain configurations, may lead to privilege escalation or account takeover. This issue is fixed in version 4.0.13.",null,[11,87,93],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-284","Improper Access Control","The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.","weakness","Incomplete","Pillar",[19,23,27,31,35,39,43,47,51,55,59,63,67,71,75,79,83],{"id":20,"name":21,"techniques":22},"CAPEC-19","Embedding Scripts within Scripts",[],{"id":24,"name":25,"techniques":26},"CAPEC-441","Malicious Logic Insertion",[],{"id":28,"name":29,"techniques":30},"CAPEC-478","Modification of Windows Service Configuration",[],{"id":32,"name":33,"techniques":34},"CAPEC-479","Malicious Root Certificate",[],{"id":36,"name":37,"techniques":38},"CAPEC-502","Intent Spoof",[],{"id":40,"name":41,"techniques":42},"CAPEC-503","WebView Exposure",[],{"id":44,"name":45,"techniques":46},"CAPEC-536","Data Injected During Configuration",[],{"id":48,"name":49,"techniques":50},"CAPEC-546","Incomplete Data Deletion in a Multi-Tenant Environment",[],{"id":52,"name":53,"techniques":54},"CAPEC-550","Install New Service",[],{"id":56,"name":57,"techniques":58},"CAPEC-551","Modify Existing Service",[],{"id":60,"name":61,"techniques":62},"CAPEC-552","Install Rootkit ",[],{"id":64,"name":65,"techniques":66},"CAPEC-556","Replace File Extension Handlers",[],{"id":68,"name":69,"techniques":70},"CAPEC-558","Replace Trusted Executable",[],{"id":72,"name":73,"techniques":74},"CAPEC-562","Modify Shared File",[],{"id":76,"name":77,"techniques":78},"CAPEC-563","Add Malicious File to Shared Webroot",[],{"id":80,"name":81,"techniques":82},"CAPEC-564","Run Software at Logon",[],{"id":84,"name":85,"techniques":86},"CAPEC-578","Disable Security Software",[],{"_key":88,"id":88,"name":89,"description":90,"type":15,"status":16,"abstraction":91,"likelihood_of_exploit":9,"capec":92},"CWE-286","Incorrect User Management","The product does not properly manage a user within its environment.","Class",[],{"_key":94,"id":94,"name":95,"description":96,"type":97,"status":98,"abstraction":9,"likelihood_of_exploit":9,"capec":99},"NVD-CWE-NOINFO","Insufficient Information","NVD uses this CWE ID when there is insufficient information to assign a specific CWE.","placeholder","NVD-Reserved",[],[101],{"_key":102,"name":103,"source":104,"url":105,"maturity":106,"reliability_score":107,"verified":108,"type":9,"platforms":109,"requires_auth":9,"exploitdb":9,"metasploit":9},"GITHUB_THORSTEN_PHPMYFAQ","Phpmyfaq","github","https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-6648-6g96-mg35","poc",0.3,false,[],[],[],[],[],[],"2025-10-03T20:06:09.404Z","2025-10-03T20:45:27.185Z","Analyzed",{"cisa_kev":108,"cisa_ransomware":108,"cisa_vendor":9,"epss_severity":119,"epss_score":120,"severity":121,"severity_score":122,"severity_version":123,"severity_source":124,"severity_vector":125,"severity_status":117},"low",0.00052,"critical",9.8,"v3.1","nvd","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",[127,135],{"url":128,"sources":129,"tags":131},"https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-9wj2-4hcm-r74j",[130,124],"cve.org",[132,133,134],"X Refsource CONFIRM","Exploit","Vendor Advisory",{"url":136,"sources":137,"tags":138},"https://github.com/thorsten/phpMyFAQ/commit/44cd20f86eb041f39d1c30a9beefad1cc61dc0ec",[130,124],[139,140],"X Refsource MISC","Patch",[],{"date":143,"score":120,"percentile":144},"2026-04-18",0.16237,[146,150,153,156,159,162,165,168,171,174,177,181,184,187,190,193,196,199,202,205,208,211,214,217,220,223,226,229,232,235,238,241,244,247,250,253,256,260,263,266,269,272,275,278,281,284,287,290,293,296,299,302,305,308,311,314,317,320,323,326,329,332,335,338,340,343,346,349,352,355,358,361,364,366,369,372,375,378,381,384,387,390,393,396,399,402,405,408,411,414],{"date":147,"score":148,"percentile":149},"2025-11-04",0.00036,0.09936,{"date":151,"score":148,"percentile":152},"2025-11-05",0.09961,{"date":154,"score":148,"percentile":155},"2025-11-06",0.10078,{"date":157,"score":148,"percentile":158},"2025-11-07",0.10106,{"date":160,"score":148,"percentile":161},"2025-11-08",0.10115,{"date":163,"score":148,"percentile":164},"2025-11-09",0.10091,{"date":166,"score":148,"percentile":167},"2025-11-10",0.10061,{"date":169,"score":148,"percentile":170},"2025-11-11",0.10076,{"date":172,"score":148,"percentile":173},"2025-11-12",0.10104,{"date":175,"score":148,"percentile":176},"2025-11-13",0.10148,{"date":178,"score":179,"percentile":180},"2025-11-14",0.00049,0.15153,{"date":182,"score":179,"percentile":183},"2025-11-15",0.15117,{"date":185,"score":179,"percentile":186},"2025-11-16",0.151,{"date":188,"score":179,"percentile":189},"2025-11-17",0.15056,{"date":191,"score":179,"percentile":192},"2025-11-18",0.10585,{"date":194,"score":179,"percentile":195},"2025-11-19",0.10604,{"date":197,"score":179,"percentile":198},"2025-11-20",0.10631,{"date":200,"score":179,"percentile":201},"2025-11-21",0.15076,{"date":203,"score":179,"percentile":204},"2025-11-22",0.15061,{"date":206,"score":179,"percentile":207},"2025-11-23",0.1505,{"date":209,"score":179,"percentile":210},"2025-11-24",0.15021,{"date":212,"score":179,"percentile":213},"2025-11-25",0.15012,{"date":215,"score":179,"percentile":216},"2025-11-26",0.14999,{"date":218,"score":179,"percentile":219},"2025-11-27",0.15013,{"date":221,"score":179,"percentile":222},"2025-11-28",0.14994,{"date":224,"score":179,"percentile":225},"2025-11-29",0.14971,{"date":227,"score":179,"percentile":228},"2025-11-30",0.14978,{"date":230,"score":179,"percentile":231},"2025-12-01",0.15016,{"date":233,"score":179,"percentile":234},"2025-12-02",0.15032,{"date":236,"score":179,"percentile":237},"2025-12-03",0.15059,{"date":239,"score":179,"percentile":240},"2025-12-04",0.1502,{"date":242,"score":179,"percentile":243},"2025-12-05",0.15088,{"date":245,"score":179,"percentile":246},"2025-12-06",0.15104,{"date":248,"score":179,"percentile":249},"2025-12-07",0.15082,{"date":251,"score":179,"percentile":252},"2025-12-08",0.15091,{"date":254,"score":179,"percentile":255},"2025-12-09",0.15148,{"date":257,"score":258,"percentile":259},"2025-12-10",0.00057,0.17722,{"date":261,"score":258,"percentile":262},"2025-12-11",0.17769,{"date":264,"score":258,"percentile":265},"2025-12-12",0.17813,{"date":267,"score":258,"percentile":268},"2025-12-13",0.1782,{"date":270,"score":258,"percentile":271},"2025-12-14",0.17765,{"date":273,"score":258,"percentile":274},"2025-12-15",0.17742,{"date":276,"score":258,"percentile":277},"2025-12-16",0.17767,{"date":279,"score":258,"percentile":280},"2025-12-17",0.17854,{"date":282,"score":258,"percentile":283},"2025-12-18",0.17945,{"date":285,"score":258,"percentile":286},"2025-12-19",0.17953,{"date":288,"score":258,"percentile":289},"2025-12-20",0.17934,{"date":291,"score":258,"percentile":292},"2025-12-21",0.17886,{"date":294,"score":258,"percentile":295},"2025-12-22",0.17838,{"date":297,"score":258,"percentile":298},"2025-12-23",0.17841,{"date":300,"score":258,"percentile":301},"2025-12-24",0.17874,{"date":303,"score":258,"percentile":304},"2025-12-25",0.17954,{"date":306,"score":258,"percentile":307},"2025-12-26",0.17944,{"date":309,"score":258,"percentile":310},"2025-12-27",0.17936,{"date":312,"score":258,"percentile":313},"2025-12-28",0.17901,{"date":315,"score":258,"percentile":316},"2025-12-29",0.17869,{"date":318,"score":258,"percentile":319},"2025-12-30",0.17883,{"date":321,"score":258,"percentile":322},"2025-12-31",0.17955,{"date":324,"score":258,"percentile":325},"2026-01-01",0.18054,{"date":327,"score":258,"percentile":328},"2026-01-02",0.18041,{"date":330,"score":258,"percentile":331},"2026-01-03",0.18022,{"date":333,"score":258,"percentile":334},"2026-01-04",0.17919,{"date":336,"score":258,"percentile":337},"2026-01-05",0.17884,{"date":339,"score":258,"percentile":313},"2026-01-06",{"date":341,"score":258,"percentile":342},"2026-01-07",0.17933,{"date":344,"score":258,"percentile":345},"2026-01-08",0.17994,{"date":347,"score":258,"percentile":348},"2026-01-09",0.17997,{"date":350,"score":258,"percentile":351},"2026-01-10",0.18011,{"date":353,"score":258,"percentile":354},"2026-01-11",0.17973,{"date":356,"score":258,"percentile":357},"2026-01-12",0.17931,{"date":359,"score":258,"percentile":360},"2026-01-13",0.17911,{"date":362,"score":258,"percentile":363},"2026-01-14",0.17961,{"date":365,"score":258,"percentile":363},"2026-01-15",{"date":367,"score":258,"percentile":368},"2026-01-16",0.17996,{"date":370,"score":258,"percentile":371},"2026-01-17",0.18002,{"date":373,"score":258,"percentile":374},"2026-01-18",0.17943,{"date":376,"score":258,"percentile":377},"2026-01-19",0.17879,{"date":379,"score":258,"percentile":380},"2026-01-20",0.17858,{"date":382,"score":258,"percentile":383},"2026-01-21",0.1783,{"date":385,"score":258,"percentile":386},"2026-01-22",0.17763,{"date":388,"score":258,"percentile":389},"2026-01-23",0.17859,{"date":391,"score":258,"percentile":392},"2026-01-24",0.17891,{"date":394,"score":258,"percentile":395},"2026-01-25",0.17816,{"date":397,"score":258,"percentile":398},"2026-01-26",0.1772,{"date":400,"score":258,"percentile":401},"2026-01-27",0.17708,{"date":403,"score":258,"percentile":404},"2026-01-28",0.17715,{"date":406,"score":258,"percentile":407},"2026-01-29",0.1769,{"date":409,"score":258,"percentile":410},"2026-01-30",0.17703,{"date":412,"score":258,"percentile":413},"2026-01-31",0.17716,{"date":415,"score":258,"percentile":416},"2026-02-01",0.17745,[418,425],{"source":130,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":419,"cvss_v4_0":9},{"baseScore":420,"baseSeverity":421,"vectorString":422,"impactScore":423,"exploitabilityScore":424},8.1,"HIGH","CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",8.7,7.2,{"source":124,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":426,"cvss_v4_0":9},{"baseScore":122,"baseSeverity":427,"vectorString":125,"impactScore":122,"exploitabilityScore":428},"CRITICAL",10,[430,437],{"ecosystem":9,"name":431,"vendor":431,"product":431,"cpe_part":432,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":433},"phpmyfaq","a",[434],{"version":435,"is_range":108,"range_type":436,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"4.0.7","cpe",{"ecosystem":9,"name":438,"vendor":439,"product":431,"cpe_part":432,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":440},"phpMyFAQ","thorsten",[441],{"version":442,"is_range":443,"range_type":130,"version_start":435,"version_start_type":444,"version_end":445,"version_end_type":446,"fixed_in":9},">= 4.0.7, \u003C 4.0.13",true,"including","4.0.13","excluding"]