Phppgadmin / Phppgadmin
13 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-60799 | phpPgAdmin 7.13.0 and earlier contains an incorrect access control vulnerability in sql.php at lines 68-76. The application allows unauthorized manipulation of… | MEDIUM | 6.1 | Nov 20, 2025 |
| CVE-2025-60798 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in display.php at line 396. The application passes user-controlled input from $_REQUEST['q… | MEDIUM | 6.5 | Nov 20, 2025 |
| CVE-2025-60797 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in dataexport.php at line 118. The application directly executes user-supplied SQL queries… | MEDIUM | 6.5 | Nov 20, 2025 |
| CVE-2025-60796 | phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting (XSS) vulnerabilities across various components. User-supplied input from $_REQUEST parame… | LOW | 2.1 | Nov 20, 2025 |
| CVE-2023-40619 | phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is direct… | CRITICAL | 9.8 | Sep 20, 2023 |
| CVE-2019-10784 | phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area, "databas… | CRITICAL | 9.6 | Feb 4, 2020 |
| CVE-2012-1600 | Multiple cross-site scripting (XSS) vulnerabilities in functions.php in phpPgAdmin before 5.0.4 allow remote attackers to inject arbitrary web script or HTML v… | MEDIUM | 4.3 | May 14, 2014 |
| CVE-2011-3598 | Multiple cross-site scripting (XSS) vulnerabilities in phpPgAdmin before 5.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) a web page… | MEDIUM | 4.3 | Oct 8, 2011 |
| CVE-2008-5587 | phpPgAdmin: directory traversal flaw in libraries/lib.inc.php | MEDIUM | 4.3 | Dec 16, 2008 |
| CVE-2007-5728 | Cross-site scripting (XSS) vulnerability in phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, allows remote attackers to inject arbitrary web script or HTML via cer… | MEDIUM | 4.3 | Oct 30, 2007 |
| CVE-2007-2865 | Cross-site scripting (XSS) vulnerability in sqledit.php in phpPgAdmin 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the server param… | HIGH | 9.3 | May 25, 2007 |
| CVE-2005-2256 | Encoded directory traversal vulnerability in phpPgAdmin 3.1 to 3.5.3 allows remote attackers to access arbitrary files via "%2e%2e%2f" (encoded dot dot) sequen… | MEDIUM | 5.0 | Jul 13, 2005 |
| CVE-2001-0479 | Directory traversal vulnerability in phpPgAdmin 2.2.1 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument… | HIGH | 7.5 | May 24, 2001 |
Showing 1 to 13 of 13 CVEs