Adminer is a single, widely deployed database-management web application that simplifies administrative access to multiple database systems, creating a high-value target for attackers despite its narrow product scope. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated tendency toward both confirmed in-the-wild exploitation and public exploit availability, and recur through weakness classes including cross-site scripting, server-side request forgery, untrusted deserialization, and input-validation flaws that are characteristic of web-facing administrative interfaces. Defenders should treat Adminer instances as a patching priority and restrict their exposure to trusted networks; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Adminer over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-21311HIGH Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Ad | Feb 11, 2021 | 7.2 | 96 | YES | YES |
CVE-2026-25892HIGH Adminer is open-source database management software. Adminer v5.4.1 and earlier has a version check mechanism where adminer.org sends signed version info via JavaScript postMessage | Feb 9, 2026 | 7.5 | 37 | NO | YES |
CVE-2021-29625MEDIUM Adminer is open-source database management software. A cross-site scripting vulnerability in Adminer versions 4.6.1 to 4.8.0 affects users of MySQL, MariaDB, PgSQL and SQLite. XSS | May 19, 2021 | 6.1 | 33 | NO | YES |
CVE-2021-43008HIGH Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by requesting the Admine | Apr 5, 2022 | 7.5 | 32 | NO | NO |
CVE-2018-7667CRITICAL Adminer through 4.3.1 has SSRF via the server parameter. | Mar 5, 2018 | 9.8 | 31 | NO | NO |
CVE-2025-43960HIGH Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object | Aug 25, 2025 | 8.6 | 27 | NO | NO |
CVE-2020-35572MEDIUM Adminer through 4.7.8 allows XSS via the history parameter to the default URI. | Feb 9, 2021 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Adminer.
Media articles that mention a CVE ID that affects a product developed by Adminer — matched by CVE ID, not by vendor name.