Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
phpMyAdmin Number Of NVD 270 CRITICAL 15 HIGH 53 MEDIUM 172 LOW 30
URL https://www.phpmyadmin.net/
Explanation phpMyAdmin is a free software tool written in PHP and intended to handle the administration of MySQL via the web. phpMyAdmin supports a wide range of operations on MySQL and MariaDB. Frequently used operations (managing databases, tables, columns, relations, indexes, users, permissions, etc.) can be performed via the user interface, with the ability to execute SQL statements directly.

Translated and excerpted from [https://www.phpmyadmin.net/].

This is a convenient way to manage MySQL without having to type SQL directly.
Tag
  • GPL v2

Add Information URL
No Type Name URL
1 https://www.phpmyadmin.net/downloads/
2 https://www.phpmyadmin.net/files/
3 https://www.phpmyadmin.net/security/

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
11 phpMyAdmin 5 5.2.3 Oct. 8, 2025 Dec. 26, 2019 2 5 4 0
12 phpMyAdmin 4 4.9.7 Oct. 15, 2020 May 3, 2013 13 30 89 16
13 phpMyAdmin 3 3.5.8.2 July 28, 2013 Sept. 27, 2008 4 8 48 10
14 phpMyAdmin 2 2.11.11.3 Feb. 11, 2011 May 12, 1999 4 22 64 10
15 phpMyAdmin 1 1.3.1 Dec. 27, 1998 Nov. 3, 1998 3 10 21 6
16 phpMyAdmin 0 0.9.0 3 9 21 6
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
11 8.0
6.0
HIGH
Network
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search act… CWE-89
SQL Injection
CVE-2020-10802 cpe:2.3:a:phpmyadmin:phpmyadmin:*:* 5.0.0
4.0.0


5.0.2
4.9.5
2024-11-21 13:56
2020-03-22
Show GitHub Exploit DB Packet Storm
12 8.0
6.0
HIGH
Network
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/Use… CWE-89
SQL Injection
CVE-2020-10804 cpe:2.3:a:phpmyadmin:phpmyadmin:*:* 5.0.0
4.0.0


5.0.2
4.9.5
2024-11-21 13:56
2020-03-22
Show GitHub Exploit DB Packet Storm
13 8.8
6.5
HIGH
Network
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this … CWE-89
SQL Injection
CVE-2020-5504 cpe:2.3:a:phpmyadmin:phpmyadmin:*:* 5.0.0
4.0.0


5.0.1
4.9.4
2024-11-21 14:34
2020-01-10
Show GitHub Exploit DB Packet Storm
14 9.8
7.5
CRITICAL
Network
phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php. NVD-CWE-noinfo
CVE-2019-19617 cpe:2.3:a:phpmyadmin:phpmyadmin:*:* 4.9.2 2024-11-21 13:35
2019-12-6
Show GitHub Exploit DB Packet Storm
15 9.8
7.5
CRITICAL
Network
An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature. CWE-89
SQL Injection
CVE-2019-18622 cpe:2.3:a:phpmyadmin:phpmyadmin:*:* 4.9.2 2024-11-21 13:33
2019-11-23
Show GitHub Exploit DB Packet Storm
16 6.5
5.8
MEDIUM
Network
A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page. CWE-352
 Origin Validation Error
CVE-2019-12922 cpe:2.3:a:phpmyadmin:phpmyadmin:*:* 4.9.0.1 2024-11-21 13:23
2019-09-13
Show GitHub Exploit DB Packet Storm
17 6.5
4.3
MEDIUM
Network
An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance… CWE-352
 Origin Validation Error
CVE-2019-12616 cpe:2.3:a:phpmyadmin:phpmyadmin:*:* 4.9.0 2024-11-21 13:23
2019-06-5
Show GitHub Exploit DB Packet Storm
18 9.8
7.5
CRITICAL
Network
An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was reported where a specially crafted database name can be used to trigger an SQL injection attack through the designer feature. CWE-89
SQL Injection
CVE-2019-11768 cpe:2.3:a:phpmyadmin:phpmyadmin:*:* 4.9.0.1 2024-11-21 13:21
2019-06-5
Show GitHub Exploit DB Packet Storm
19 5.9
4.3
MEDIUM
Network
An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the serv… NVD-CWE-noinfo
CVE-2019-6799 cpe:2.3:a:phpmyadmin:phpmyadmin:*:* 4.0.0 4.8.4 2024-11-21 13:47
2019-01-27
Show GitHub Exploit DB Packet Storm
20 9.8
7.5
CRITICAL
Network
An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported where a specially crafted username can be used to trigger a SQL injection attack through the designer feature. CWE-89
SQL Injection
CVE-2019-6798 cpe:2.3:a:phpmyadmin:phpmyadmin:*:* 4.5.0 4.8.4 2024-11-21 13:47
2019-01-27
Show GitHub Exploit DB Packet Storm