Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2023-25727
In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop in…
phpMyAdmin
4.9.11 / 5.2.1+
CRITICAL 9.8
CVE-2020-22452
SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_…
phpMyAdmin
5.2.0+
HIGH 7.5
CVE-2022-0813
PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang para…
phpMyAdmin
after 5.1.1
MEDIUM 6.1
CVE-2022-23808EPSS 8%
An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS o…
phpMyAdmin
5.1.2+
HIGH 8.8
CVE-2020-22278
phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based …
phpMyAdmin
after 5.0.2
MEDIUM 6.1
CVE-2020-11441
phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on a…
phpMyAdmin
No fix yet
CRITICAL 9.8
CVE-2019-11768
An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was reported where a specially crafted database name can be used to trigger an …
phpMyAdmin
4.9.0.1+
MEDIUM 6.5
CVE-2019-12616EPSS 19%
An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin u…
phpMyAdmin
4.9.0+
CRITICAL 9.8
CVE-2019-6798
An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported where a specially crafted username can be used to trigger a SQL inje…
phpMyAdmin
after 4.8.4
HIGH 8.8
CVE-2018-19969
phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is …
phpMyAdmin
4.8.4+
MEDIUM 6.1
CVE-2018-15605
An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted file to m…
phpMyAdmin
4.8.3+
HIGH 8.8
CVE-2018-12613EPSS 98%
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vu…
phpMyAdmin
4.8.2+
MEDIUM 6.1
CVE-2018-12581
An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been found where an attacker can …
phpMyAdmin
4.8.2+
HIGH 8.8
CVE-2018-10188
phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations…
phpMyAdmin
No fix yet
MEDIUM 5.4
CVE-2018-7260
Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin before 4.7.8 allows remote authenticated users to inject arbitrary w…
phpMyAdmin
4.7.8+
HIGH 8.8
CVE-2017-1000499EPSS 8%
phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible t…
phpMyAdmin
4.7.7+
HIGH 8.8
CVE-2017-1000017
phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appropriate permissions is able to connect to an arbitrary MySQL server
phpMyAdmin
4.0.10.19+
HIGH 7.5
CVE-2017-1000014
phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a DOS weakness in the table editing functionality
phpMyAdmin
Patch available
HIGH 7.5
CVE-2017-1000016
A weakness was discovered where an attacker can inject arbitrary values in to the browser cookies. This is a re-issue of an incomplete fix from PMASA…
phpMyAdmin
Mitigation only
HIGH 7.5
CVE-2017-1000018
phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication status by using a specially crafted table name
phpMyAdmin
4.0.10.19 / 4.4.15.10+
MEDIUM 6.1
CVE-2017-1000013
phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to an open redirect weakness
phpMyAdmin
Patch available
MEDIUM 6.1
CVE-2017-1000015
phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a CSS injection attack through crafted cookie parameters
phpMyAdmin
Mitigation only
HIGH 8.6
CVE-2016-6621
The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers to conduct server-side reque…
phpMyAdmin
after 4.0.10.18
CRITICAL 9.8
CVE-2016-9866
An issue was discovered in phpMyAdmin. When the arg_separator is different from its default & value, the CSRF token was not properly stripped from th…
phpMyAdmin
Patch available
CRITICAL 9.8
CVE-2016-9865
An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnseria…
phpMyAdmin
Patch available
HIGH 7.5
CVE-2016-9864
An issue was discovered in phpMyAdmin. With a crafted username or a table name, it was possible to inject SQL statements in the tracking functionalit…
phpMyAdmin
Patch available
HIGH 7.5
CVE-2016-9863
An issue was discovered in phpMyAdmin. With a very large request to table partitioning function, it is possible to invoke a Denial of Service (DoS) a…
phpMyAdmin
Patch available
HIGH 7.5
CVE-2016-9862
An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4…
phpMyAdmin
Patch available
HIGH 7.5
CVE-2016-9861
An issue was discovered in phpMyAdmin. Due to the limitation in URL matching, it was possible to bypass the URL white-list protection. All 4.6.x vers…
phpMyAdmin
Patch available
MEDIUM 5.9
CVE-2016-9860
An issue was discovered in phpMyAdmin. An unauthenticated user can execute a denial of service attack when phpMyAdmin is running with $cfg['AllowArbi…
phpMyAdmin
Patch available