phpmyadmin
272 tracked vulnerabilities.
CVE-2025-24530
MEDIUM
phpMyAdmin 5.0.0-5.2.1 - Stored Cross-Site Scripting via Crafted Table or Database Name
Jan 23, 2025
CVSS 6.4
EPSS 0.00
CVE-2025-24529
MEDIUM
phpMyAdmin 5.0.0-5.2.1 - Stored Cross-Site Scripting in Insert Tab
Jan 23, 2025
CVSS 6.4
EPSS 0.00
CVE-2023-25727
MEDIUM
phpMyAdmin < 4.9.11 and 5.x < 5.2.1 - Authenticated Stored Cross-Site Scripting via SQL File Upload
Feb 13, 2023
CVSS 5.4
EPSS 0.10
CVE-2022-0813
MEDIUM
phpMyAdmin < 5.1.1 and 5.1.2 - Exposure of Sensitive Information via Invalid Requests
Mar 10, 2022
CVSS 5.3
EPSS 0.00
CVE-2022-23808
MEDIUM
NUCLEI
phpMyAdmin 5.1.0-5.1.1 - Cross-Site Scripting in Setup Script
Jan 22, 2022
CVSS 6.1
EPSS 0.52
CVE-2022-23807
MEDIUM
phpMyAdmin <4.9.8, <5.1.2 - Auth Bypass
Jan 22, 2022
CVSS 4.3
EPSS 0.00
CVE-2020-22452
CRITICAL
phpMyAdmin 5.0.0-5.0.1 and 5.0.2-5.1.4 - SQL Injection via tbl_storage_engine or tbl_collation Parameters
Jan 26, 2023
CVSS 9.8
EPSS 0.03
CVE-2020-22278
HIGH
phpMyAdmin < 5.0.2 - CSV Injection via Export Section
Nov 04, 2020
CVSS 8.8
EPSS 0.00
CVE-2020-26935
CRITICAL
NUCLEI
phpMyAdmin <4.9.6, <5.0.3 - SQL Injection
Oct 10, 2020
CVSS 9.8
EPSS 0.90
CVE-2020-26934
MEDIUM
phpMyAdmin 4.9.0-4.9.5 - Cross-Site Scripting via Transformation Feature
Oct 10, 2020
CVSS 6.1
EPSS 0.03
CVE-2020-11441
MEDIUM
NUCLEI
phpMyAdmin 5.0.2 - CRLF Injection via Login Form Fields
Mar 31, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-10803
MEDIUM
phpMyAdmin <4.9.5-5.0.2 - SQL Injection
Mar 22, 2020
CVSS 5.4
EPSS 0.04
CVE-2020-10802
HIGH
phpMyAdmin <4.9.5, 5.x <5.0.2 - SQL Injection
Mar 22, 2020
CVSS 8.0
EPSS 0.02
CVE-2020-10804
HIGH
phpMyAdmin <4.9.5-5.0.2 - SQL Injection
Mar 22, 2020
CVSS 8.0
EPSS 0.02
CVE-2020-5504
HIGH
phpMyAdmin <4.9.4-5.0.1 - SQL Injection
Jan 09, 2020
CVSS 8.8
EPSS 0.22
CVE-2019-19617
CRITICAL
phpMyAdmin <4.9.2 - Info Disclosure
Dec 06, 2019
CVSS 9.8
EPSS 0.01
CVE-2019-18622
CRITICAL
phpMyAdmin < 4.9.2 - SQL Injection via Designer Feature
Nov 22, 2019
CVSS 9.8
EPSS 0.01
CVE-2019-12922
MEDIUM
phpMyAdmin 4.9.0.1 - Cross-Site Request Forgery in Setup Page
Sep 13, 2019
CVSS 6.5
EPSS 0.42
CVE-2019-12616
MEDIUM
phpMyAdmin < 4.9.0 - Cross-Site Request Forgery
Jun 05, 2019
CVSS 6.5
EPSS 0.55
CVE-2019-11768
CRITICAL
phpMyAdmin <4.9.0.1 - SQL Injection
Jun 05, 2019
CVSS 9.8
EPSS 0.02
CVE-2019-6799
MEDIUM
NUCLEI
phpMyAdmin <4.8.5 - Info Disclosure
Jan 26, 2019
CVSS 5.9
EPSS 0.77
CVE-2019-6798
CRITICAL
phpMyAdmin < 4.8.5 - SQL Injection via Designer Feature
Jan 26, 2019
CVSS 9.8
EPSS 0.01
CVE-2018-19970
MEDIUM
phpMyAdmin < 4.8.4 - Stored Cross-Site Scripting via Crafted Database/Table Name
Dec 11, 2018
CVSS 6.1
EPSS 0.02
CVE-2018-19969
HIGH
phpMyAdmin 4.7.0-4.7.5 and 4.8.0-4.8.3 - Cross-Site Request Forgery
Dec 11, 2018
CVSS 8.8
EPSS 0.00
CVE-2018-19968
MEDIUM
phpMyAdmin <4.8.4 - Info Disclosure
Dec 11, 2018
CVSS 6.5
EPSS 0.03
Products
Quick Filters