VYPR
Vendor

Phpmoadmin

Products
1
CVEs
6
Across products
6
Status
Private

Products

1

Recent CVEs

6
  • CVE-2019-25451HigFeb 20, 2026
    risk 0.57cvss 8.8epss 0.00

    phpMoAdmin 1.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized database operations by crafting malicious requests. Attackers can trick authenticated users into submitting GET requests to moadmin.php with parameters like action,…

  • CVE-2019-25454MedFeb 20, 2026
    risk 0.40cvss 6.1epss 0.00

    phpMoAdmin 1.1.5 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the collection parameter. Attackers can send GET requests to moadmin.php with script payloads in the collection parameter…

  • CVE-2019-25453MedFeb 20, 2026
    risk 0.40cvss 6.1epss 0.00

    phpMoAdmin 1.1.5 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the newdb parameter. Attackers can craft URLs with JavaScript payloads in the newdb parameter of moadmin.php to execute…

  • CVE-2025-63948MedDec 18, 2025
    risk 0.35cvss 5.4epss 0.00

    A SQL Injection vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary SQL commands via the dbname parameter, potentially leading to information disclosure or database manipulation.

  • CVE-2025-63947MedDec 18, 2025
    risk 0.35cvss 5.4epss 0.00

    A Reflected Cross-Site Scripting (XSS) vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary web script or HTML via the dbname parameter after a user is authenticated.

  • CVE-2015-2208Mar 12, 2015
    risk 0.08cvss epss 0.62

    The saveObject function in moadmin.php in phpMoAdmin 1.1.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the object parameter.