Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Adminer

First CVE: Mar 5, 2018Active for: 8 yearsTotal CVEs: 7

Adminer is a single, widely deployed database-management web application that simplifies administrative access to multiple database systems, creating a high-value target for attackers despite its narrow product scope. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated tendency toward both confirmed in-the-wild exploitation and public exploit availability, and recur through weakness classes including cross-site scripting, server-side request forgery, untrusted deserialization, and input-validation flaws that are characteristic of web-facing administrative interfaces. Defenders should treat Adminer instances as a patching priority and restrict their exposure to trusted networks; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
14.3%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Adminer over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 5, 2018
8 years ago
Most Recent CVE
Feb 9, 2026
167 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-21311HIGH
Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Ad
Feb 11, 20217.296YESYES
CVE-2026-25892HIGH
Adminer is open-source database management software. Adminer v5.4.1 and earlier has a version check mechanism where adminer.org sends signed version info via JavaScript postMessage
Feb 9, 20267.537NOYES
CVE-2021-29625MEDIUM
Adminer is open-source database management software. A cross-site scripting vulnerability in Adminer versions 4.6.1 to 4.8.0 affects users of MySQL, MariaDB, PgSQL and SQLite. XSS
May 19, 20216.133NOYES
CVE-2021-43008HIGH
Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by requesting the Admine
Apr 5, 20227.532NONO
CVE-2018-7667CRITICAL
Adminer through 4.3.1 has SSRF via the server parameter.
Mar 5, 20189.831NONO
CVE-2025-43960HIGH
Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object
Aug 25, 20258.627NONO
CVE-2020-35572MEDIUM
Adminer through 4.7.8 allows XSS via the history parameter to the default URI.
Feb 9, 20216.120NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
29%
57%
14%
Severity distribution among all CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (71.4%)
Unknown0 (0.0%)
Required2 (28.6%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
1 CVE
14.3% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
42.9% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Adminer.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Adminer — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Adminer's Products

View all 2 CNAs →

Top CWEs