Vulnerability index

Browse CVEs

156 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2023-25727 In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop in… phpMyAdmin 4.9.11 / 5.2.1+ Fix from $1,6002023-02-13 CRITICAL 9.8 CVE-2020-22452 SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_… phpMyAdmin 5.2.0+ Fix from $2,3002023-01-26 HIGH 7.5 CVE-2022-0813 PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang para… phpMyAdmin after 5.1.1 Fix from $1,9502022-03-10 MEDIUM 6.1 CVE-2022-23808EPSS 8% An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS o… phpMyAdmin 5.1.2+ Fix from $1,6002022-01-22 HIGH 8.8 CVE-2020-22278 phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based … phpMyAdmin after 5.0.2 Fix from $1,9502020-11-04 MEDIUM 6.1 CVE-2020-11441 phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on a… phpMyAdmin No fix yet Fix from $1,6002020-03-31 CRITICAL 9.8 CVE-2019-11768 An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was reported where a specially crafted database name can be used to trigger an … phpMyAdmin 4.9.0.1+ Fix from $2,3002019-06-05 MEDIUM 6.5 CVE-2019-12616EPSS 19% An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin u… phpMyAdmin 4.9.0+ Fix from $1,6002019-06-05 CRITICAL 9.8 CVE-2019-6798 An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported where a specially crafted username can be used to trigger a SQL inje… phpMyAdmin after 4.8.4 Fix from $2,3002019-01-26 HIGH 8.8 CVE-2018-19969 phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is … phpMyAdmin 4.8.4+ Fix from $1,9502018-12-11 MEDIUM 6.1 CVE-2018-15605 An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted file to m… phpMyAdmin 4.8.3+ Fix from $1,6002018-08-24 HIGH 8.8 CVE-2018-12613EPSS 98% An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vu… phpMyAdmin 4.8.2+ Fix from $1,9502018-06-21 MEDIUM 6.1 CVE-2018-12581 An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been found where an attacker can … phpMyAdmin 4.8.2+ Fix from $1,6002018-06-21 HIGH 8.8 CVE-2018-10188 phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations… phpMyAdmin No fix yet Fix from $1,9502018-04-19 MEDIUM 5.4 CVE-2018-7260 Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin before 4.7.8 allows remote authenticated users to inject arbitrary w… phpMyAdmin 4.7.8+ Fix from $1,6002018-02-21 HIGH 8.8 CVE-2017-1000499EPSS 8% phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible t… phpMyAdmin 4.7.7+ Fix from $1,9502018-01-03 HIGH 8.8 CVE-2017-1000017 phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appropriate permissions is able to connect to an arbitrary MySQL server phpMyAdmin 4.0.10.19+ Fix from $1,9502017-07-17 HIGH 7.5 CVE-2017-1000014 phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a DOS weakness in the table editing functionality phpMyAdmin Patch available Fix from $1,9502017-07-17 HIGH 7.5 CVE-2017-1000016 A weakness was discovered where an attacker can inject arbitrary values in to the browser cookies. This is a re-issue of an incomplete fix from PMASA… phpMyAdmin Mitigation only Fix from $1,9502017-07-17 HIGH 7.5 CVE-2017-1000018 phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication status by using a specially crafted table name phpMyAdmin 4.0.10.19 / 4.4.15.10+ Fix from $1,9502017-07-17 MEDIUM 6.1 CVE-2017-1000013 phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to an open redirect weakness phpMyAdmin Patch available Fix from $1,6002017-07-17 MEDIUM 6.1 CVE-2017-1000015 phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a CSS injection attack through crafted cookie parameters phpMyAdmin Mitigation only Fix from $1,6002017-07-17 HIGH 8.6 CVE-2016-6621 The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers to conduct server-side reque… phpMyAdmin after 4.0.10.18 Fix from $1,9502017-01-31 CRITICAL 9.8 CVE-2016-9866 An issue was discovered in phpMyAdmin. When the arg_separator is different from its default & value, the CSRF token was not properly stripped from th… phpMyAdmin Patch available Fix from $2,3002016-12-11 CRITICAL 9.8 CVE-2016-9865 An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnseria… phpMyAdmin Patch available Fix from $2,3002016-12-11 HIGH 7.5 CVE-2016-9864 An issue was discovered in phpMyAdmin. With a crafted username or a table name, it was possible to inject SQL statements in the tracking functionalit… phpMyAdmin Patch available Fix from $1,9502016-12-11 HIGH 7.5 CVE-2016-9863 An issue was discovered in phpMyAdmin. With a very large request to table partitioning function, it is possible to invoke a Denial of Service (DoS) a… phpMyAdmin Patch available Fix from $1,9502016-12-11 HIGH 7.5 CVE-2016-9862 An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4… phpMyAdmin Patch available Fix from $1,9502016-12-11 HIGH 7.5 CVE-2016-9861 An issue was discovered in phpMyAdmin. Due to the limitation in URL matching, it was possible to bypass the URL white-list protection. All 4.6.x vers… phpMyAdmin Patch available Fix from $1,9502016-12-11 MEDIUM 5.9 CVE-2016-9860 An issue was discovered in phpMyAdmin. An unauthenticated user can execute a denial of service attack when phpMyAdmin is running with $cfg['AllowArbi… phpMyAdmin Patch available Fix from $1,6002016-12-11