Phpliteadmin Project maintains a lightweight web-based administration interface for SQLite databases, a modestly scoped tool often deployed for quick database management in smaller web applications. The observed vulnerability pattern centers on cross-site request forgery, reflecting the web interface's exposure to state-changing operations without adequate request-origin validation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpliteadmin Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10362CRITICAL An issue was discovered in phpLiteAdmin 1.9.5 through 1.9.7.1. Due to loose comparison with '==' instead of '===' in classes/Authorization.php for the user-provided login password, | Apr 25, 2018 | 9.8 | 28 | NO | NO |
CVE-2015-6517MEDIUM Cross-site request forgery (CSRF) vulnerability in phpLiteAdmin 1.1 allows remote attackers to hijack the authentication of users for requests that drop database tables via the dro | Aug 18, 2015 | 6.8 | 27 | NO | YES |
CVE-2015-6518MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in phpLiteAdmin 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, (2) droptable parameter | Aug 18, 2015 | 4.3 | 22 | NO | YES |
CVE-2021-46709MEDIUM phpLiteAdmin through 1.9.8.2 allows XSS via the index.php newRows parameter (aka num or number). | Mar 13, 2022 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpliteadmin Project.
Media articles that mention a CVE ID that affects a product developed by Phpliteadmin Project — matched by CVE ID, not by vendor name.