MEDIUMVulnerability

CVE-2026-75920

phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at content.zip, exposing sensitive files including database credentials. Unauthenticated attackers can race concurrent requests to download the temporary ZIP file before deletion, or exploit XSS in admin contexts to trigger authenticated backups and retrieve the archive.

Properties

severity
MEDIUM
score
5.3
epss_score
0.00334
cve_id
CVE-2026-75920
vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
published_at
2026-08-19T14:17:42.527
last_modified
2026-09-01T16:05:18.150
epss_percentile
0.26185

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

AFFECTS_PRODUCT (1)

[Product]

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Insecure Temporary File

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-75920 — Ninja Signal Threat Intelligence | Ninja Signal