Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
phpMyAdmin Number Of NVD 270 CRITICAL 15 HIGH 53 MEDIUM 172 LOW 30
URL https://www.phpmyadmin.net/
Explanation phpMyAdmin is a free software tool written in PHP and intended to handle the administration of MySQL via the web. phpMyAdmin supports a wide range of operations on MySQL and MariaDB. Frequently used operations (managing databases, tables, columns, relations, indexes, users, permissions, etc.) can be performed via the user interface, with the ability to execute SQL statements directly.

Translated and excerpted from [https://www.phpmyadmin.net/].

This is a convenient way to manage MySQL without having to type SQL directly.
Tag
  • GPL v2

Add Information URL
No Type Name URL
1 https://www.phpmyadmin.net/downloads/
2 https://www.phpmyadmin.net/files/
3 https://www.phpmyadmin.net/security/

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
51 phpMyAdmin 5 5.2.3 Oct. 8, 2025 Dec. 26, 2019 2 5 4 0
52 phpMyAdmin 4 4.9.7 Oct. 15, 2020 May 3, 2013 13 30 89 16
53 phpMyAdmin 3 3.5.8.2 July 28, 2013 Sept. 27, 2008 4 8 48 10
54 phpMyAdmin 2 2.11.11.3 Feb. 11, 2011 May 12, 1999 4 22 64 10
55 phpMyAdmin 1 1.3.1 Dec. 27, 1998 Nov. 3, 1998 3 10 21 6
56 phpMyAdmin 0 0.9.0 3 9 21 6
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
51 5.3
5.0
MEDIUM
Network
An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the… CWE-200
Information Exposure
CVE-2016-9853 cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.4:*
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:*
cpe:2.3:a:phpmyadmin:phpmyadmin:4…
2024-11-21 12:01
2016-12-11
Show GitHub Exploit DB Packet Storm
52 5.3
5.0
MEDIUM
Network
An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the… CWE-200
Information Exposure
CVE-2016-9852 cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.4:*
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:*
cpe:2.3:a:phpmyadmin:phpmyadmin:4…
2024-11-21 12:01
2016-12-11
Show GitHub Exploit DB Packet Storm
53 5.3
5.0
MEDIUM
Network
An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to bypass the logout timeout. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) … CWE-254
 7PK - Security Features
CVE-2016-9851 cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.4:*
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:*
cpe:2.3:a:phpmyadmin:phpmyadmin:4…
2024-11-21 12:01
2016-12-11
Show GitHub Exploit DB Packet Storm
54 5.3
5.0
MEDIUM
Network
An issue was discovered in phpMyAdmin. Username matching for the allow/deny rules may result in wrong matches and detection of the username in the rule due to non-constant execution time. All 4.6.x v… CWE-254
 7PK - Security Features
CVE-2016-9850 cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.4:*
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:*
cpe:2.3:a:phpmyadmin:phpmyadmin:4…
2024-11-21 12:01
2016-12-11
Show GitHub Exploit DB Packet Storm
55 9.8
7.5
CRITICAL
Network
An issue was discovered in phpMyAdmin. It is possible to bypass AllowRoot restriction ($cfg['Servers'][$i]['AllowRoot']) and deny rules for username by using Null Byte in the username. All 4.6.x vers… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-9849 cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.4:*
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:*
cpe:2.3:a:phpmyadmin:phpmyadmin:4…
2024-11-21 12:01
2016-12-11
Show GitHub Exploit DB Packet Storm
56 5.3
5.0
MEDIUM
Network
An issue was discovered in phpMyAdmin. phpinfo (phpinfo.php) shows PHP information including values of HttpOnly cookies. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4… CWE-200
Information Exposure
CVE-2016-9848 cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.4:*
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:*
cpe:2.3:a:phpmyadmin:phpmyadmin:4…
2024-11-21 12:01
2016-12-11
Show GitHub Exploit DB Packet Storm
57 5.3
5.0
MEDIUM
Network
An issue was discovered in phpMyAdmin. When the user does not specify a blowfish_secret key for encrypting cookies, phpMyAdmin generates one at runtime. A vulnerability was reported where the way thi… CWE-310
Cryptographic Issues
CVE-2016-9847 cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.4:*
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:*
cpe:2.3:a:phpmyadmin:phpmyadmin:4…
2024-11-21 12:01
2016-12-11
Show GitHub Exploit DB Packet Storm
58 8.1
6.8
HIGH
Network
An issue was discovered in phpMyAdmin. phpMyAdmin can be used to trigger a remote code execution attack against certain PHP installations that are running with the dbase extension. All 4.6.x versions… NVD-CWE-noinfo
CVE-2016-6633 cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:*
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.2:*
cpe:2.3:a:phpmyadmin:phpmyadmin:4…
2024-11-21 11:56
2016-12-11
Show GitHub Exploit DB Packet Storm
59 5.9
4.3
MEDIUM
Network
An issue was discovered in phpMyAdmin where, under certain conditions, phpMyAdmin may not delete temporary files during the import of ESRI files. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (… CWE-399
 Resource Management Errors
CVE-2016-6632 cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:*
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.2:*
cpe:2.3:a:phpmyadmin:phpmyadmin:4…
2024-11-21 11:56
2016-12-11
Show GitHub Exploit DB Packet Storm
60 7.5
8.5
HIGH
Network
An issue was discovered in phpMyAdmin. A user can execute a remote code execution attack against a server when phpMyAdmin is being run as a CGI application. Under certain server configurations, a use… CWE-78
OS Command 
CVE-2016-6631 cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:*
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.2:*
cpe:2.3:a:phpmyadmin:phpmyadmin:4…
2024-11-21 11:56
2016-12-11
Show GitHub Exploit DB Packet Storm