Vulnerabilities > Phpmyfaq > Phpmyfaq > 2.8.9

DATE CVE VULNERABILITY TITLE RISK
2017-07-12 CVE-2017-11187 Improper Restriction of Excessive Authentication Attempts vulnerability in PHPmyfaq
phpMyFAQ before 2.9.8 does not properly mitigate brute-force attacks that try many passwords in attempted logins quickly.
network
low complexity
phpmyfaq CWE-307
5.0
2017-04-07 CVE-2017-7579 Cross-site Scripting vulnerability in PHPmyfaq
inc/PMF/Faq.php in phpMyFAQ before 2.9.7 has XSS in the question field.
network
phpmyfaq CWE-79
4.3