The phpMyFAQ Team has learned of a security issue that has been discovered in phpMyFAQ 3.0.6 and earlier. phpMyFAQ contains a cross-site scripting (XSS) vulnerability.
phpMyFAQ does not implement sufficient checks to avoid XSS injection for displaying tags.
The phpMyFAQ Team has released the new phpMyFAQ versions 3.0.7 and 3.1.0-alpha.3 which fix the vulnerability. All users of affected phpMyFAQ versions are encouraged to upgrade as soon as possible to this latest version.
There's no workaround except installing phpMyFAQ 3.0.7 or 3.1.0-alpha.3.
The phpMyFAQ teams would like to thank Curtis Robinson from Florida Tech for the responsible disclosure of the vulnerability and helping to fix it.