Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Phpmyadmin

First CVE: Jun 27, 2001Active for: 25 yearsTotal CVEs: 272
48.3
VTI Score
High

phpMyAdmin is a widely deployed, open-source database-management interface for MySQL and MariaDB that, despite being a single product, occupies a prominent position in the vulnerability landscape due to its ubiquity across web hosting, development, and administrative environments. Vulnerabilities affecting phpMyAdmin skew toward moderate severity outcomes and frequently acquire public exploit tooling; the exposure recurs persistently through application-layer input-handling weakness classes including cross-site scripting, SQL injection, improper input validation, and sensitive-information disclosure. These weakness patterns reflect the product's role as a trusted web interface to powerful database operations, where input validation gaps and output-encoding failures can directly translate to unauthorized database access or session hijacking. Defenders should treat phpMyAdmin instances as high-priority patching targets, especially internet-facing deployments, and should monitor this vendor's advisories regularly given the combination of widespread deployment and durable exploitation appeal. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
272
Total CVEs
More Total CVEs than 100% of tracked vendors
13.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
5.9
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked vendors
0.4%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Phpmyadmin over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 27, 2001
25 years ago
Most Recent CVE
Jan 23, 2025
547 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (272 CVEs).

272 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2009-1151CRITICAL
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configurati
Mar 26, 20099.899YESYES
CVE-2018-12613HIGH
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vulnerability comes from a portio
Jun 21, 20188.894NOYES
CVE-2016-5734CRITICAL
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the preg_replace e (aka eval) modifier, which
Jul 3, 20169.887NOYES
CVE-2012-5159HIGH
phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modification (Trojan Horse) in server_s
Sep 25, 20127.583NOYES
CVE-2020-26935CRITICAL
An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements
Oct 10, 20209.877NOYES
CVE-2020-5504HIGH
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creati
Jan 9, 20208.861NOYES
CVE-2013-3238MEDIUM
phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 allows remote authenticated users to execute arbitrary code via a /e\x00 sequence, which is not properly handled before makin
Apr 26, 20136.052NOYES
CVE-2012-5469HIGH
The Portable phpMyAdmin plugin before 1.3.1 for WordPress allows remote attackers to bypass authentication and obtain phpMyAdmin console access via a direct request to wp-content/p
Dec 20, 20127.548NOYES
CVE-2019-12616MEDIUM
An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the
Jun 5, 20196.543NOYES
CVE-2009-1285HIGH
Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote attackers to inject arbitrary PHP
Apr 16, 20097.542NOYES
View all 272 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products272 CVEs
11%
64%
19%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (0.4%)
Network120 (44.1%)
Unknown151 (55.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low104 (38.2%)
High17 (6.3%)
Unknown151 (55.5%)
User Interaction
None80 (29.4%)
Unknown151 (55.5%)
Required41 (15.1%)
Privileges Required
Low33 (12.1%)
High0 (0.0%)
None88 (32.4%)
Unknown151 (55.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (272 CVEs).

CISA KEV
1 CVE
0.4% of CVEs· 99th percentile
Metasploit
6 CVEs
2.2% of CVEs· 97th percentile
Nuclei
6 CVEs
2.2% of CVEs· 95th percentile
ExploitDB
38 CVEs
14.0% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Phpmyadmin.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Phpmyadmin — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Phpmyadmin's Products

View all 4 CNAs →

Top CWEs