CVEs (270)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface. |
SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php. |
PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section. |
An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection. |
An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login insta...Show more |
phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents. |
4Debian FedoraprojectOpensuse+1 more5Backports Sle Debian LinuxFedora+2 moreJun 17, 2026 Oct 10, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker coul...Show more |
4Debian FedoraprojectOpensuse+1 more5Backports Sle Debian LinuxFedora+2 moreJun 17, 2026 Oct 10, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link. |
phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specificall...Show more |
5Debian FedoraprojectOpensuse+2 more6Backports Sle Debian LinuxFedora+3 moreJun 17, 2026 Mar 22, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.ph...Show more |
5Debian FedoraprojectOpensuse+2 more6Backports Sle Debian LinuxFedora+3 moreJun 17, 2026 Mar 22, 2020 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/cla...Show more |
4Fedoraproject OpensusePhpmyadmin+1 more5Backports Sle FedoraLeap+2 moreJun 17, 2026 Mar 22, 2020 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A mal...Show more |
3Debian PhpmyadminSuse3Debian Linux PhpmyadminSuse Linux Enterprise ServerJun 17, 2026 Jan 9, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker mus...Show more |
2Debian Phpmyadmin2Debian Linux PhpmyadminJun 17, 2026 Dec 6, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php. |
3Fedoraproject OpensusePhpmyadmin4Backports Sle FedoraLeap+1 moreJun 17, 2026 Nov 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature. |
2Fedoraproject Phpmyadmin2Fedora PhpmyadminJun 17, 2026 Sep 13, 2019 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page. |
An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance through a broken <im...Show more |
An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was reported where a specially crafted database name can be used to trigger an SQL injection attack through the designer feature. |
2Debian Phpmyadmin2Debian Linux PhpmyadminJun 17, 2026 Jan 26, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web serve...Show more |
An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported where a specially crafted username can be used to trigger a SQL injection attack through the designer feature. |