← Back

Phpmoadmin

phpmoadmin

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Phpmoadmin
phpmoadmin

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phpmoadmin
1Phpmoadmin
Mar 2, 2026
Feb 20, 2026
5.3 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
phpMoAdmin 1.1.5 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the collection parameter. Attackers can send GET requests to moadmin...Show more
phpMoAdmin 1.1.5 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the collection parameter. Attackers can send GET requests to moadmin.php with script payloads in the collection parameter during collection creation to execute arbitrary JavaScript in users' browsers.Show less
1Phpmoadmin
1Phpmoadmin
Feb 24, 2026
Feb 20, 2026
5.1 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
phpMoAdmin 1.1.5 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the newdb parameter. Attackers can craft URLs with JavaScript pay...Show more
phpMoAdmin 1.1.5 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the newdb parameter. Attackers can craft URLs with JavaScript payloads in the newdb parameter of moadmin.php to execute arbitrary code in users' browsers when they visit the malicious link.Show less
1Phpmoadmin
1Phpmoadmin
Mar 2, 2026
Feb 20, 2026
5.3 MEDIUM· v4
8.8 HIGH· v3
N/A· v2
phpMoAdmin 1.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized database operations by crafting malicious requests. Attackers can trick authenticated users into submitti...Show more
phpMoAdmin 1.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized database operations by crafting malicious requests. Attackers can trick authenticated users into submitting GET requests to moadmin.php with parameters like action, db, and collection to create, drop, or repair databases and collections without user consent.Show less