\"@evil.com. PHP's FILTER_VALIDATE_EMAIL accepts this email as valid. The email is stored in the database without HTML sanitization and later rendered in the admin FAQ editor template using Twig's |raw filter, which bypasses auto-esc","image":"https://o3.security/opengraph.png","datePublished":"2026-04-02T14:43:14.799Z","dateModified":"2026-08-07T11:48:53.165341928Z","url":"https://o3.security/vulnerability/CVE-2026-32629","inLanguage":"en","author":{"@id":"https://o3.security/#organization"},"publisher":{"@id":"https://o3.security/#organization"},"mainEntityOfPage":{"@type":"WebPage","@id":"https://o3.security/vulnerability/CVE-2026-32629"},"speakable":{"@type":"SpeakableSpecification","cssSelector":["h1",".vuln-summary",".vuln-severity",".vuln-mitigation"]},"about":[{"@type":"SoftwareApplication","name":"thorsten/phpmyfaq","applicationCategory":"Packagist","softwareVersion":"4.1.1"},{"@type":"SoftwareApplication","name":"phpmyfaq/phpmyfaq","applicationCategory":"Packagist","softwareVersion":"4.1.1"}],"citation":[{"@type":"WebPage","url":"https://github.com/thorsten/phpMyFAQ/releases/tag/4.1.1"},{"@type":"WebPage","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32629.json"},{"@type":"WebPage","url":"https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-98gw-w575-h2ph"},{"@type":"WebPage","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32629"}]}\"@evil.com. PHP's FILTER_VALIDATE_EMAIL accepts this email as valid. The email is stored in the database without HTML sanitization and later rendered in the admin FAQ editor template using Twig's |raw filter, which bypasses auto-esc","url":"https://o3.security/vulnerability/CVE-2026-32629","identifier":"CVE-2026-32629","datePublished":"2026-04-02T14:43:14.799Z","dateModified":"2026-08-07T11:48:53.165341928Z","inLanguage":"en","license":"https://creativecommons.org/licenses/by/4.0/","keywords":["CVE-2026-32629","CWE-20","CWE-79","CVE","vulnerability","security advisory"],"creator":{"@id":"https://o3.security/#organization"},"isAccessibleForFree":true}\"@evil.com. PHP's FILTER_VALIDATE_EMAIL accepts this email as valid. The email is stored in the database without HTML sanitization and later rendered in the admin FAQ editor template using Twig's |raw filter, which bypasses auto-escaping entirely. This issue has been patched in version 4.1.1."}},{"@type":"Question","name":"How severe is CVE-2026-32629?","acceptedAnswer":{"@type":"Answer","text":"No CVSS score has been assigned to CVE-2026-32629 yet. Review the advisory details and affected package list to assess your exposure."}},{"@type":"Question","name":"Which packages are affected by CVE-2026-32629?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-32629 affects the following packages: thorsten/phpmyfaq (Packagist), phpmyfaq/phpmyfaq (Packagist). Ecosystems affected: Packagist."}},{"@type":"Question","name":"How do I fix CVE-2026-32629?","acceptedAnswer":{"@type":"Answer","text":"Update thorsten/phpmyfaq to 4.1.1 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-32629 is resolved across your whole dependency graph."}},{"@type":"Question","name":"How do I detect CVE-2026-32629 in my Packagist dependencies?","acceptedAnswer":{"@type":"Answer","text":"Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for thorsten/phpmyfaq. O3's reachability analysis confirms whether the vulnerable code path is actually invoked in your application, so you act on real exposure instead of every transitive match."}},{"@type":"Question","name":"How do I mitigate CVE-2026-32629 if there is no patch (or I can't update yet)?","acceptedAnswer":{"@type":"Answer","text":"If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands."}},{"@type":"Question","name":"How does O3 Security protect against CVE-2026-32629?","acceptedAnswer":{"@type":"Answer","text":"O3 pinpoints whether CVE-2026-32629 is reachable in your code and exactly where to fix it, then blocks exploitation in production at runtime until the patched version is deployed."}},{"@type":"Question","name":"Is CVE-2026-32629 actively exploited in the wild?","acceptedAnswer":{"@type":"Answer","text":"No public exploit code has been indexed for CVE-2026-32629 yet. This does not mean the vulnerability cannot be exploited — absence of public exploits does not imply safety. Apply the recommended fix and use O3 Security to monitor your exposure."}},{"@type":"Question","name":"What type of vulnerability is CVE-2026-32629?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-32629 is classified as Improper Input Validation (CWE-20), Cross-site Scripting (XSS) (CWE-79). These weakness types describe the underlying flaw category, which helps determine the potential impact and the right class of mitigation. This is a high-impact weakness class that often enables remote code execution or data exposure."}},{"@type":"Question","name":"When was CVE-2026-32629 published, and has it been updated?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-32629 was published on April 2, 2026 and was last updated on August 7, 2026. Advisory data evolves as severity scores, affected ranges, and exploit intelligence are revised — always check the latest version of the advisory before acting."}}]}
Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🐘 Packagist

CVE-2026-32629

CVE-2026-32629 is a Improper Input Validation vulnerability in thorsten/phpmyfaq. O3 Security confirms whether CVE-2026-32629 is actually reachable in your code before you act, and blocks exploitation at runtime until you patch.

phpMyFAQ: Stored XSS via Unsanitized Email Field in Admin FAQ Editor

Also known asGHSA-98gw-w575-h2ph
Published
Apr 2, 2026
Updated
Aug 7, 2026
Affected
2 pkgs
Patched
2 / 2
Exploits
None indexed

Blast Radius

2 pkgs affected
🐘thorsten/phpmyfaq🐘phpmyfaq/phpmyfaq

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Packagist packages — download data is not available via public APIs for these ecosystems.

Description

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, an unauthenticated attacker can submit a guest FAQ with an email address that is syntactically valid per RFC 5321 (quoted local part) yet contains raw HTML — for example "<script>alert(1)</script>"@evil.com. PHP's FILTER_VALIDATE_EMAIL accepts this email as valid. The email is stored in the database without HTML sanitization and later rendered in the admin FAQ editor template using Twig's |raw filter, which bypasses auto-escaping entirely. This issue has been patched in version 4.1.1.

Affected Packages

2 total 2 fixed
EcosystemPackageVulnerable rangeFix
🐘Packagistthorsten/phpmyfaqall versions4.1.1
🐘Packagistphpmyfaq/phpmyfaqall versions4.1.1

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for thorsten/phpmyfaq. O3's reachability analysis confirms whether the vulnerable code path is actually invoked in your application, so you act on real exposure instead of every transitive match.

  2. Fix

    Update thorsten/phpmyfaq to 4.1.1 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-32629 is resolved across your whole dependency graph.

  3. Workarounds

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

  4. How O3 protects you

    O3 pinpoints whether CVE-2026-32629 is reachable in your code and exactly where to fix it, then blocks exploitation in production at runtime until the patched version is deployed.

Tailored to CVE-2026-32629. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.

Frequently Asked Questions

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, an unauthenticated attacker can submit a guest FAQ with an email address that is syntactically valid per RFC 5321 (quoted local part) yet contains raw HTML — for example "<script>alert(1)</script>"@evil.com. PHP's FILTER_VALIDATE_EMAIL accepts this email as valid. The email is stored in the database without HTML sanitization and later rendered in the admin FAQ editor template using Twig's |raw filter, which bypasses auto-escaping entirely. This issue has been patched in version 4.1.1.
O3 Security · Impact-Aware SCA

Is CVE-2026-32629 in your dependencies?

O3 detects CVE-2026-32629 across Packagist dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.