LOWVulnerability

CVE-2026-85586

phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA protection and submit unlimited questions directly, causing database pollution and triggering outgoing mail notifications.

Properties

cve_id
CVE-2026-85586
signal_observed_at
2026-09-16T01:21:39+00:00
published_at
2026-09-04T12:17:20.737
last_modified
2026-09-10T16:17:59.233

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Improper Control of Interaction Frequency

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-85586 — Ninja Signal Threat Intelligence | Ninja Signal