VYPR

adminer

by Vrana

Source repositories

CVEs (17)

  • CVE-2021-21311HigKEVFeb 11, 2021
    risk 0.60cvss 7.2epss 0.98

    Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This is fixed in version…

  • CVE-2026-56705CriAug 25, 2026
    risk 0.57cvss 9.8epss 0.01

    Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote…

  • CVE-2026-56702HigAug 25, 2026
    risk 0.50cvss 8.8epss 0.01

    Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can upload PHP webshells to columns ending in…

  • CVE-2026-15686HigAug 20, 2026
    risk 0.47cvss 7.2epss 0.01

    Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adminer. Authentication is required to exploit this vulnerability. The specific…

  • CVE-2026-34968HigAug 25, 2026
    risk 0.46cvss 8.1epss 0.01

    Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the database-list drop action fails to validate file extensions before deletion. An authenticated attacker can submit arbitrary relative file paths in the db[] parameter to delete any…

  • CVE-2021-29625HigMay 19, 2021
    risk 0.43cvss 7.5epss 0.10

    Adminer is open-source database management software. A cross-site scripting vulnerability in Adminer versions 4.6.1 to 4.8.0 affects users of MySQL, MariaDB, PgSQL and SQLite. XSS is in most cases prevented by strict CSP in all modern browsers. The only exception is when Adminer…

  • CVE-2026-25892HigFeb 9, 2026
    risk 0.42cvss 7.5epss 0.02

    Adminer is open-source database management software. Adminer v5.4.1 and earlier has a version check mechanism where adminer.org sends signed version info via JavaScript postMessage, which the browser then POSTs to ?script=version. This endpoint lacks origin validation and…

  • CVE-2026-56703HigAug 25, 2026
    risk 0.40cvss 7.2epss 0.01

    Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can execute VACUUM INTO to write PHP code to arbitrary file paths and execute commands on the server.

  • CVE-2026-63771HigJul 20, 2026
    risk 0.39cvss 7.1epss 0.00

    Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by injecting arbitrary values through the unsanitized X-Forwarded-Prefix HTTP header used in Set-Cookie path attributes. Attackers can exploit a misconfigured…

  • CVE-2026-56706MedAug 25, 2026
    risk 0.37cvss 6.8epss 0.00

    Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked value in every token (format (rand XOR secret):rand), allowing anyone who observes a single CSRF token (e.g., via network sniffing, log files, Referrer header, or XSS) to recover the…

  • CVE-2026-100695MedSep 26, 2026
    risk 0.33cvss 6.1epss 0.00

    Adminer before 6.0.2 contains a cross-site scripting vulnerability where the CONNECTION_ID() database result is interpolated into JavaScript without proper escaping, allowing a malicious database server to execute arbitrary JavaScript in the authenticated Adminer origin. In…

  • CVE-2026-56704MedAug 25, 2026
    risk 0.33cvss 6.1epss 0.00

    Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without proper validation. Attackers controlling a rogue MySQL server can return crafted version strings that break out of the JavaScript context and execute arbitrary…

  • CVE-2026-100698MedSep 26, 2026
    risk 0.31cvss 5.8epss 0.00

    Adminer 5.5.1 through 6.0.1 improperly parses the login 'server' string in the host_port() function in adminer/include/functions.inc.php. The port capture group requires pure digits anchored to the end of the string, so any server value with a non-digit tail fails the regex and…

  • CVE-2026-34964MedAug 25, 2026
    risk 0.31cvss 5.8epss 0.00

    Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server field validator, which only inspects leading integers for privileged ports and fails to reject non-numeric port values. Attackers can inject PDO DSN keys like host= and port=…

  • CVE-2026-34959MedAug 25, 2026
    risk 0.31cvss 4.7epss 0.00

    Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUEST_URI"] with no trusted-proxy check and no validation of the prefix value. An attacker can supply an absolute URL (e.g. X-Forwarded-Prefix: https://evil.example) that flows into…

  • CVE-2026-34967MedAug 25, 2026
    risk 0.28cvss 5.4epss 0.00

    Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in the ns parameter of plugins/sql-log.php. An authenticated user can supply path traversal sequences in the ns parameter to write arbitrary .sql files with…

  • CVE-2026-16434LowAug 25, 2026
    risk 0.08cvss —epss 0.00

    Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix vulnerability (GHSA-8478-xrj3-h9c2). The validation guard (bootstrap.inc.php) only rejects prefixes matching ^/[^/], blocking //evil.com but allowing values such as /\evil.com…