CVE-2026-24422 | thorsten phpMyFAQ up to 4.0.16 API Endpoint list information disclosure (GHSA-j4rc-96xj-gvqc / EUVD-2026-4257)
A vulnerability marked as problematic has been reported in thorsten phpMyFAQ up to 4.0.16. This affects the function OpenQuestionController::list of the component API Endpoint. The manipulation leads to information disclosure.
This vulnerability is listed as CVE-2026-24422. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.