CVE-2026-48488: phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing
Attachment passwords are hashed using SHA-1, a cryptographically broken algorithm. SHA-1 has been vulnerable to collision attacks since 2017 (SHAttered).
References
Code Behaviors & Features
Detect and mitigate CVE-2026-48488 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →