VYPR

Vendor CVEs

PhpMyAdmin

All CVEs

443 total · sorted by risk
  • CVE-2016-5739HigJul 3, 2016
    risk 0.42cvss 7.5epss 0.03

    The Transformation implementation in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not use the no-referrer Content Security Policy (CSP) protection mechanism, which makes it easier for remote attackers to conduct CSRF attacks by reading an…

  • CVE-2016-5706HigJul 3, 2016
    risk 0.42cvss 7.5epss 0.03

    js/get_scripts.js.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to cause a denial of service via a large array in the scripts parameter.

  • CVE-2016-2041HigFeb 20, 2016
    risk 0.42cvss 7.5epss 0.03

    libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier for remote attackers to bypass intended access restrictions by measuring time…

  • CVE-2016-1927HigFeb 20, 2016
    risk 0.42cvss 7.5epss 0.03

    The suggestPassword function in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 relies on the Math.random JavaScript function, which makes it easier for remote attackers to guess passwords via a brute-force approach.

  • CVE-2023-1886HigApr 5, 2023
    risk 0.41cvss 7.3epss 0.01

    Authentication Bypass by Capture-replay in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

  • CVE-2016-6628MedDec 11, 2016
    risk 0.41cvss 6.3epss 0.01

    An issue was discovered in phpMyAdmin. An attacker may be able to trigger a user to download a specially crafted malicious SVG file. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

  • CVE-2005-4349MedDec 19, 2005
    risk 0.41cvss 6.3epss 0.01

    SQL injection vulnerability in server_privileges.php in phpMyAdmin 2.7.0 allows remote authenticated users to execute arbitrary SQL commands via the (1) dbname and (2) checkprivs parameters. NOTE: the vendor and a third party have disputed this issue, saying that the main task…

  • CVE-2024-28105HigMar 25, 2024
    risk 0.40cvss 7.2epss 0.01

    phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The category image upload function in phpmyfaq is vulnerable to manipulation of the `Content-type` and `lang` parameters, allowing attackers to upload malicious files with a…

  • CVE-2020-26934MedOct 10, 2020
    risk 0.40cvss 6.1epss 0.02

    phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.

  • CVE-2020-11441MedMar 31, 2020
    risk 0.40cvss 6.1epss 0.02

    phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specifically exploitable.

  • CVE-2019-12616MedJun 5, 2019
    risk 0.40cvss 6.5epss 0.19

    An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance through a broken tag pointing at the victim's phpMyAdmin database, and…

  • CVE-2019-6799MedJan 26, 2019
    risk 0.40cvss 5.9epss 0.15

    An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web server's user can access. This is related to the…

  • CVE-2018-19970MedDec 11, 2018
    risk 0.40cvss 6.1epss 0.02

    In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name.

  • CVE-2018-15899MedAug 27, 2018
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in MiniCMS 1.10. There is a post.php?date= XSS vulnerability.

  • CVE-2017-15809MedOct 23, 2017
    risk 0.40cvss 6.1epss 0.01

    In phpMyFaq before 2.9.9, there is XSS in admin/tags.main.php via a crafted tag.

  • CVE-2017-1000015MedJul 17, 2017
    risk 0.40cvss 6.1epss 0.01

    phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a CSS injection attack through crafted cookie parameters

  • CVE-2017-1000013MedJul 17, 2017
    risk 0.40cvss 6.1epss 0.01

    phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to an open redirect weakness

  • CVE-2017-7579MedApr 7, 2017
    risk 0.40cvss 6.1epss 0.01

    inc/PMF/Faq.php in phpMyFAQ before 2.9.7 has XSS in the question field.

  • CVE-2016-9857MedDec 11, 2016
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in phpMyAdmin. XSS is possible because of a weakness in a regular expression used in some JavaScript processing. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

  • CVE-2016-9856MedDec 11, 2016
    risk 0.40cvss 6.1epss 0.01

    An XSS issue was discovered in phpMyAdmin because of an improper fix for CVE-2016-2559 in PMASA-2016-10. This issue is resolved by using a copy of a hash to avoid a race condition. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior…

  • CVE-2016-6615MedDec 11, 2016
    risk 0.40cvss 6.1epss 0.01

    XSS issues were discovered in phpMyAdmin. This affects navigation pane and database/table hiding feature (a specially-crafted database name can be used to trigger an XSS attack); the "Tracking" feature (a specially-crafted query can be used to trigger an XSS attack); and GIS…

  • CVE-2016-6608MedDec 11, 2016
    risk 0.40cvss 6.1epss 0.01

    XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the "Remove partitioning" functionality. Specially crafted database names can trigger the XSS attack. All 4.6.x versions (prior to 4.6.4) are affected.

  • CVE-2016-6607MedDec 11, 2016
    risk 0.40cvss 6.1epss 0.01

    XSS issues were discovered in phpMyAdmin. This affects Zoom search (specially crafted column content can be used to trigger an XSS attack); GIS editor (certain fields in the graphical GIS editor are not properly escaped and can be used to trigger an XSS attack); Relation view;…

  • CVE-2016-5099MedJul 5, 2016
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web script or HTML via special characters that are mishandled during double URL decoding.

  • CVE-2016-2560MedMar 1, 2016
    risk 0.40cvss 6.1epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.15, 4.4.x before 4.4.15.5, and 4.5.x before 4.5.5.1 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted Host HTTP header, related to libraries/Config.class.php; (2)…

  • CVE-2023-0793HigFeb 12, 2023
    risk 0.39cvss 7.1epss 0.01

    Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

  • CVE-2019-12922MedSep 13, 2019
    risk 0.39cvss 6.5epss 0.10

    A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.

  • CVE-2016-9860MedDec 11, 2016
    risk 0.39cvss 5.9epss 0.02

    An issue was discovered in phpMyAdmin. An unauthenticated user can execute a denial of service attack when phpMyAdmin is running with $cfg['AllowArbitraryServer']=true. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to…

  • CVE-2016-6632MedDec 11, 2016
    risk 0.39cvss 5.9epss 0.02

    An issue was discovered in phpMyAdmin where, under certain conditions, phpMyAdmin may not delete temporary files during the import of ESRI files. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

  • CVE-2016-6624MedDec 11, 2016
    risk 0.39cvss 5.9epss 0.02

    An issue was discovered in phpMyAdmin involving improper enforcement of the IP-based authentication rules. When phpMyAdmin is used with IPv6 in a proxy server environment, and the proxy server is in the allowed range but the attacking computer is not allowed, this vulnerability…

  • CVE-2011-4107MedNov 17, 2011
    risk 0.39cvss 6.5epss 0.13

    The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external…

  • CVE-2026-46361MedMay 15, 2026
    risk 0.38cvss 6.9epss 0.00

    phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in search.twig where result.question and result.answerPreview are rendered with the raw filter, disabling autoescape protection. Attackers with FAQ editor privileges can inject HTML-entity-encoded…

  • CVE-2017-15727MedOct 22, 2017
    risk 0.38cvss 5.4epss 0.02

    In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment.

  • CVE-2016-6622MedDec 11, 2016
    risk 0.38cvss 5.9epss 0.02

    An issue was discovered in phpMyAdmin. An unauthenticated user is able to execute a denial-of-service (DoS) attack by forcing persistent connections when phpMyAdmin is running with $cfg['AllowArbitraryServer']=true. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to…

  • CVE-2016-2562MedMar 1, 2016
    risk 0.37cvss 6.8epss 0.01

    The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to spoof these servers and obtain sensitive information via a crafted certificate.

  • CVE-2022-4407MedDec 11, 2022
    risk 0.36cvss 6.1epss 0.04

    Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.9.

  • CVE-2022-3766MedOct 31, 2022
    risk 0.36cvss 6.1epss 0.06

    Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

  • CVE-2013-1937MedApr 16, 2013
    risk 0.36cvss 6.1epss 0.06

    Multiple cross-site scripting (XSS) vulnerabilities in tbl_gis_visualization.php in phpMyAdmin 3.5.x before 3.5.8 might allow remote attackers to inject arbitrary web script or HTML via the (1) visualizationSettings[width] or (2) visualizationSettings[height] parameter. NOTE: a…

  • CVE-2008-1567MedMar 31, 2008
    risk 0.36cvss 5.5epss 0.00

    phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.

  • CVE-2026-49205MedJun 18, 2026
    risk 0.35cvss 6.5epss 0.00

    phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryController. CVE-2026-24421 addressed this in the BackupController by adding: $this->userHasPermission(PermissionType::BACKUP). The same fix was not applied to 4…

  • CVE-2026-46362MedMay 15, 2026
    risk 0.35cvss 6.5epss 0.00

    phpMyFAQ before 4.1.2 contains an authorization bypass vulnerability in AbstractAdministrationController::userHasPermission() that fails to terminate execution after sending a forbidden response. Attackers can access all permission-protected admin pages by requesting their URLs…

  • CVE-2026-45008MedMay 15, 2026
    risk 0.35cvss 6.5epss 0.00

    phpMyFAQ before 4.1.2 contains a path traversal vulnerability in Client::deleteClientFolder that allows admins with INSTANCE_DELETE permission to delete arbitrary directories. Attackers can submit traversal sequences like https://../../../ in the client URL parameter to…

  • CVE-2025-24530MedJan 23, 2025
    risk 0.35cvss 6.4epss 0.00

    An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the check tables feature. A crafted table or database name could be used for XSS.

  • CVE-2024-24574MedFeb 5, 2024
    risk 0.35cvss 6.5epss 0.01

    phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Unsafe echo of filename in phpMyFAQ\phpmyfaq\admin\attachments.php leads to allowed execution of JavaScript code in client side (XSS). This vulnerability has been patched in…

  • CVE-2024-22208MedFeb 5, 2024
    risk 0.35cvss 6.5epss 0.01

    phpMyFAQ is an Open Source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The 'sharing FAQ' functionality allows any unauthenticated actor to misuse the phpMyFAQ application to send arbitrary emails to a large range of targets. The phpMyFAQ…

  • CVE-2023-0792MedFeb 12, 2023
    risk 0.35cvss 6.5epss 0.01

    Code Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

  • CVE-2022-0813MedMar 10, 2022
    risk 0.35cvss 5.3epss 0.01

    PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section.

  • CVE-2020-10803MedMar 22, 2020
    risk 0.35cvss 5.4epss 0.01

    In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker…

  • CVE-2018-19968MedDec 11, 2018
    risk 0.35cvss 6.5epss 0.03

    An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the…

  • CVE-2016-9859MedDec 11, 2016
    risk 0.35cvss 5.3epss 0.02

    An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in import feature. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

Page 3 of 9