phpMyAdmin is a widely deployed, open-source database-management interface for MySQL and MariaDB that, despite being a single product, occupies a prominent position in the vulnerability landscape due to its ubiquity across web hosting, development, and administrative environments. Vulnerabilities affecting phpMyAdmin skew toward moderate severity outcomes and frequently acquire public exploit tooling; the exposure recurs persistently through application-layer input-handling weakness classes including cross-site scripting, SQL injection, improper input validation, and sensitive-information disclosure. These weakness patterns reflect the product's role as a trusted web interface to powerful database operations, where input validation gaps and output-encoding failures can directly translate to unauthorized database access or session hijacking. Defenders should treat phpMyAdmin instances as high-priority patching targets, especially internet-facing deployments, and should monitor this vendor's advisories regularly given the combination of widespread deployment and durable exploitation appeal. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpmyadmin over time
Signals from CVEs in this vendor scope (272 CVEs).
272 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-1151CRITICAL Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configurati | Mar 26, 2009 | 9.8 | 99 | YES | YES |
CVE-2018-12613HIGH An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vulnerability comes from a portio | Jun 21, 2018 | 8.8 | 94 | NO | YES |
CVE-2016-5734CRITICAL phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the preg_replace e (aka eval) modifier, which | Jul 3, 2016 | 9.8 | 87 | NO | YES |
CVE-2012-5159HIGH phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modification (Trojan Horse) in server_s | Sep 25, 2012 | 7.5 | 83 | NO | YES |
CVE-2020-26935CRITICAL An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements | Oct 10, 2020 | 9.8 | 77 | NO | YES |
CVE-2020-5504HIGH In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creati | Jan 9, 2020 | 8.8 | 61 | NO | YES |
CVE-2013-3238MEDIUM phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 allows remote authenticated users to execute arbitrary code via a /e\x00 sequence, which is not properly handled before makin | Apr 26, 2013 | 6.0 | 52 | NO | YES |
CVE-2012-5469HIGH The Portable phpMyAdmin plugin before 1.3.1 for WordPress allows remote attackers to bypass authentication and obtain phpMyAdmin console access via a direct request to wp-content/p | Dec 20, 2012 | 7.5 | 48 | NO | YES |
CVE-2019-12616MEDIUM An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the | Jun 5, 2019 | 6.5 | 43 | NO | YES |
CVE-2009-1285HIGH Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote attackers to inject arbitrary PHP | Apr 16, 2009 | 7.5 | 42 | NO | YES |
Signals from CVEs in this vendor scope (272 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpmyadmin.
Media articles that mention a CVE ID that affects a product developed by Phpmyadmin — matched by CVE ID, not by vendor name.