{"id":"CVE-2026-48488","aliases":["GHSA-58fg-62fg-3fcj"],"url":"https://o3.security/vulnerability/CVE-2026-48488","summary":"phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing","details":"phpMyFAQ is an open source FAQ web application. Prior to version 4.1.4, attachment passwords are hashed using SHA-1, a cryptographically broken algorithm. SHA-1 has been vulnerable to collision attacks since 2017 (SHAttered). Version 4.1.4 fixes the issue.","published":"2026-06-08T15:15:12.595Z","modified":"2026-08-12T03:51:35.611530346Z","cvss":null,"epss":{"score":0.00182,"percentile":0.07847,"asOf":"2026-09-08"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"thorsten/phpmyfaq","fixedVersion":"4.1.4"},{"ecosystem":"Packagist","name":"phpmyfaq/phpmyfaq","fixedVersion":"4.1.4"}],"fix":{"url":"https://github.com/thorsten/phpMyFAQ/commit/1aa9be6f8a2fa5c527c983826205229fc3129718","label":"thorsten/phpMyFAQ@1aa9be6"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48488.json"},{"type":"ADVISORY","url":"https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-58fg-62fg-3fcj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48488"},{"type":"FIX","url":"https://github.com/thorsten/phpMyFAQ/commit/1aa9be6f8a2fa5c527c983826205229fc3129718"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:35.611530346Z"}}