CVE ID :CVE-2026-35676 Published : May 28, 2026, 4:16 p.m. | 2ย hours, 8ย minutes ago Description :phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint that allows attackers to change account passwords without token validation. Attackers can enumerate valid username and email pairs and force immediate password changes
phpMyFAQ
Exploit
CVE-2026-35676
MITRE CVE High
Refer to CVE-2026-35676 NVD advisory