In phpMyFAQ prior to 2.9.9, there is Stored Cross-site Scripting (XSS) via metaDescription or metaKeywords.
phpmyfaq phpmyfaq