Vulnerability index

Browse CVEs

156 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

phpMyAdmin MEDIUM 5.4
CVE-2023-25727

In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop in…

Fix: 4.9.11 / 5.2.1+
Fix from $1,600 2023-02-13
phpMyAdmin CRITICAL 9.8
CVE-2020-22452

SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_…

Fix: 5.2.0+
Fix from $2,300 2023-01-26
phpMyAdmin HIGH 7.5
CVE-2022-0813

PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang para…

Fix: after 5.1.1
Fix from $1,950 2022-03-10
phpMyAdmin MEDIUM 6.1
CVE-2022-23808EPSS 8%

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS o…

Fix: 5.1.2+
Fix from $1,600 2022-01-22
phpMyAdmin HIGH 8.8
CVE-2020-22278

phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based …

Fix: after 5.0.2
Fix from $1,950 2020-11-04
phpMyAdmin MEDIUM 6.1
CVE-2020-11441

phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on a…

No fix yet
Fix from $1,600 2020-03-31
phpMyAdmin CRITICAL 9.8
CVE-2019-11768

An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was reported where a specially crafted database name can be used to trigger an …

Fix: 4.9.0.1+
Fix from $2,300 2019-06-05
phpMyAdmin MEDIUM 6.5
CVE-2019-12616EPSS 19%

An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin u…

Fix: 4.9.0+
Fix from $1,600 2019-06-05
phpMyAdmin CRITICAL 9.8
CVE-2019-6798

An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported where a specially crafted username can be used to trigger a SQL inje…

Fix: after 4.8.4
Fix from $2,300 2019-01-26
phpMyAdmin HIGH 8.8
CVE-2018-19969

phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is …

Fix: 4.8.4+
Fix from $1,950 2018-12-11
phpMyAdmin MEDIUM 6.1
CVE-2018-15605

An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted file to m…

Fix: 4.8.3+
Fix from $1,600 2018-08-24
phpMyAdmin HIGH 8.8
CVE-2018-12613EPSS 98%

An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vu…

Fix: 4.8.2+
Fix from $1,950 2018-06-21
phpMyAdmin MEDIUM 6.1
CVE-2018-12581

An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been found where an attacker can …

Fix: 4.8.2+
Fix from $1,600 2018-06-21
phpMyAdmin HIGH 8.8
CVE-2018-10188

phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations…

No fix yet
Fix from $1,950 2018-04-19
phpMyAdmin MEDIUM 5.4
CVE-2018-7260

Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin before 4.7.8 allows remote authenticated users to inject arbitrary w…

Fix: 4.7.8+
Fix from $1,600 2018-02-21
phpMyAdmin HIGH 8.8
CVE-2017-1000499EPSS 8%

phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible t…

Fix: 4.7.7+
Fix from $1,950 2018-01-03
phpMyAdmin HIGH 8.8
CVE-2017-1000017

phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appropriate permissions is able to connect to an arbitrary MySQL server

Fix: 4.0.10.19+
Fix from $1,950 2017-07-17
phpMyAdmin HIGH 7.5
CVE-2017-1000014

phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a DOS weakness in the table editing functionality

Patch available
Fix from $1,950 2017-07-17
phpMyAdmin HIGH 7.5
CVE-2017-1000016

A weakness was discovered where an attacker can inject arbitrary values in to the browser cookies. This is a re-issue of an incomplete fix from PMASA…

Mitigation only
Fix from $1,950 2017-07-17
phpMyAdmin HIGH 7.5
CVE-2017-1000018

phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication status by using a specially crafted table name

Fix: 4.0.10.19 / 4.4.15.10+
Fix from $1,950 2017-07-17
phpMyAdmin MEDIUM 6.1
CVE-2017-1000013

phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to an open redirect weakness

Patch available
Fix from $1,600 2017-07-17
phpMyAdmin MEDIUM 6.1
CVE-2017-1000015

phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a CSS injection attack through crafted cookie parameters

Mitigation only
Fix from $1,600 2017-07-17
phpMyAdmin HIGH 8.6
CVE-2016-6621

The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers to conduct server-side reque…

Fix: after 4.0.10.18
Fix from $1,950 2017-01-31
phpMyAdmin CRITICAL 9.8
CVE-2016-9866

An issue was discovered in phpMyAdmin. When the arg_separator is different from its default & value, the CSRF token was not properly stripped from th…

Patch available
Fix from $2,300 2016-12-11
phpMyAdmin CRITICAL 9.8
CVE-2016-9865

An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnseria…

Patch available
Fix from $2,300 2016-12-11
phpMyAdmin HIGH 7.5
CVE-2016-9864

An issue was discovered in phpMyAdmin. With a crafted username or a table name, it was possible to inject SQL statements in the tracking functionalit…

Patch available
Fix from $1,950 2016-12-11
phpMyAdmin HIGH 7.5
CVE-2016-9863

An issue was discovered in phpMyAdmin. With a very large request to table partitioning function, it is possible to invoke a Denial of Service (DoS) a…

Patch available
Fix from $1,950 2016-12-11
phpMyAdmin HIGH 7.5
CVE-2016-9862

An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4…

Patch available
Fix from $1,950 2016-12-11
phpMyAdmin HIGH 7.5
CVE-2016-9861

An issue was discovered in phpMyAdmin. Due to the limitation in URL matching, it was possible to bypass the URL white-list protection. All 4.6.x vers…

Patch available
Fix from $1,950 2016-12-11
phpMyAdmin MEDIUM 5.9
CVE-2016-9860

An issue was discovered in phpMyAdmin. An unauthenticated user can execute a denial of service attack when phpMyAdmin is running with $cfg['AllowArbi…

Patch available
Fix from $1,600 2016-12-11