Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-5734

87
FAUCET Score

CVE-2016-5734 is a critical remote code execution vulnerability affecting phpMyAdmin versions 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3. The flaw stems from improper delimiter handling in the preg_replace function, allowing attackers to execute arbitrary PHP code, notably through the table search-and-replace feature. This vulnerability carries a CVSS score of 9.8 (CRITICAL), indicating a severe risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. The high EPSS score and FAUCET Risk Score of 100/100 further emphasize its significant exploitability and potential impact. While not listed on the CISA KEV catalog, exploit intelligence confirms the existence of public exploit code, including a Metasploit module and an ExploitDB entry for authenticated remote code execution. Despite the availability of exploit code, there is minimal community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
4.0.0CPE matchmatch criteria
cpe:2.3:a:phpmyadmin:phpmyadmin:4.0.0:*:*:*:*:*:*:*
4.0.1CPE matchmatch criteria
cpe:2.3:a:phpmyadmin:phpmyadmin:4.0.1:*:*:*:*:*:*:*
4.0.2CPE matchmatch criteria
cpe:2.3:a:phpmyadmin:phpmyadmin:4.0.2:*:*:*:*:*:*:*
4.0.3CPE matchmatch criteria
cpe:2.3:a:phpmyadmin:phpmyadmin:4.0.3:*:*:*:*:*:*:*
4.0.4CPE matchmatch criteria
cpe:2.3:a:phpmyadmin:phpmyadmin:4.0.4:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

9.8CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
81.37%
Probability of exploitation in next 30 days
EPSS Percentile
99.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
Metasploit: phpMyAdmin Authenticated Remote Code Execution · Jun 23, 2016
ExploitDB: EDB-40185 · Jul 29, 2016
This CVE's current EPSS score of 0.8137 is in the 98th percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

composerpatch availablevia ghsa
Product: phpmyadmin/phpmyadminFixed in: 4.0.10.16
composerpatch availablevia ghsa
Product: phpmyadmin/phpmyadminFixed in: 4.4.15.7
composerpatch availablevia ghsa
Product: phpmyadmin/phpmyadminFixed in: 4.6.3
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-rv57-479x-x4qvcritical

phpMyAdmin Code Injection vulnerability

May 17, 2022

References

github.com / phpmyadmin/phpmyadmin/commit/1cc7466db3a05e95fe57a6702f41773e6829d54b
Patch
github.com / phpmyadmin/phpmyadmin/commit/4bcc606225f15bac0b07780e74f667f6ac283da7
Patch
security.gentoo.org / glsa/201701-32
exploit-db.com / exploits/40185
ExploitThird Party AdvisoryVDB Entry
phpmyadmin.net / security/PMASA-2016-27
PatchVendor Advisory
securityfocus.com / bid/91387