CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2025-24530 MEDIUM

An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the check tables feature. A crafted table or database name…

CVSS 6.4 EPSS 0.42% Jan 23, 2025
CVE-2025-24529 MEDIUM

An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the Insert tab.

CVSS 6.4 EPSS 0.41% Jan 23, 2025
CVE-2023-25727 MEDIUM

In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.

CVSS 5.4 EPSS 1.16% Feb 13, 2023
CVE-2020-22452 CRITICAL

SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation…

CVSS 9.8 EPSS 1.71% Jan 26, 2023
CVE-2022-0813 HIGH

PhpMyAdmin exposure of sensitive information

CVSS 7.5 EPSS 1.30% Mar 9, 2022
CVE-2022-23808 MEDIUM

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML inj…

CVSS 6.1 EPSS 7.94% Jan 22, 2022
CVE-2022-23807 MEDIUM

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their accou…

CVSS 4.3 EPSS 0.74% Jan 22, 2022
CVE-2020-22278 HIGH

phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the dat…

CVSS 8.8 EPSS 1.53% Nov 4, 2020
CVE-2020-26934 MEDIUM

phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.

CVSS 6.1 EPSS 1.90% Oct 10, 2020
CVE-2020-26935 CRITICAL

An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin pro…

CVSS 9.8 EPSS 67.08% Oct 10, 2020
CVE-2020-11441 MEDIUM

phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error pa…

CVSS 6.1 EPSS 2.41% Mar 31, 2020
CVE-2020-10802 HIGH

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when g…

CVSS 8.0 EPSS 1.82% Mar 22, 2020
CVE-2020-10803 MEDIUM

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack t…

CVSS 5.4 EPSS 1.37% Mar 22, 2020
CVE-2020-10804 HIGH

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/…

CVSS 8.0 EPSS 2.35% Mar 22, 2020
CVE-2020-5504 HIGH

In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own…

CVSS 8.8 EPSS 38.78% Jan 9, 2020
CVE-2019-19617 CRITICAL

phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php.

CVSS 9.8 EPSS 2.59% Dec 6, 2019
CVE-2019-18622 CRITICAL

An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature.

CVSS 9.8 EPSS 2.24% Nov 22, 2019
CVE-2019-12922 MEDIUM

A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.

CVSS 6.5 EPSS 10.14% Sep 13, 2019
CVE-2019-12616 MEDIUM

An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The a…

CVSS 6.5 EPSS 19.18% Jun 5, 2019
CVE-2019-11768 CRITICAL

An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was reported where a specially crafted database name can be used to trigger an SQL inject…

CVSS 9.8 EPSS 3.65% Jun 5, 2019
CVE-2019-6799 MEDIUM

An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, a…

CVSS 5.9 EPSS 14.83% Jan 26, 2019
CVE-2019-6798 CRITICAL

An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported where a specially crafted username can be used to trigger a SQL injection atta…

CVSS 9.8 EPSS 3.47% Jan 26, 2019
CVE-2018-19970 MEDIUM

In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database…

CVSS 6.1 EPSS 2.24% Dec 11, 2018
CVE-2018-19969 HIGH

phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is possible t…

CVSS 8.8 EPSS 1.06% Dec 11, 2018
CVE-2018-19968 MEDIUM

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have…

CVSS 6.5 EPSS 2.89% Dec 11, 2018

Showing 1 to 25 CVEs · page 1 (more available)