phpPgAdmin is a lightweight web-based administration interface for PostgreSQL databases that, despite its narrow product scope, has occupied a visible role in database management deployments and attracts sustained public exploit development. Its vulnerability profile centers on input-handling weaknesses such as cross-site scripting and path traversal, along with NVD categorization gaps, reflecting the exposure challenges inherent in exposing database management functions through a web interface. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phppgadmin over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2865HIGH Cross-site scripting (XSS) vulnerability in sqledit.php in phpPgAdmin 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the server parameter. | May 25, 2007 | 9.3 | 39 | NO | YES |
CVE-2007-5728MEDIUM Cross-site scripting (XSS) vulnerability in phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, allows remote attackers to inject arbitrary web script or HTML via certain input available | Oct 30, 2007 | 4.3 | 34 | NO | YES |
CVE-2008-5587MEDIUM Directory traversal vulnerability in libraries/lib.inc.php in phpPgAdmin 4.2.1 and earlier, when register_globals is enabled, allows remote attackers to read arbitrary files via a | Dec 16, 2008 | 4.3 | 33 | NO | YES |
CVE-2019-10784CRITICAL phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area, "database.php" does not verif | Feb 4, 2020 | 9.6 | 31 | NO | NO |
CVE-2023-40619CRITICAL phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is directly passed to the PHP | Sep 20, 2023 | 9.8 | 27 | NO | NO |
CVE-2005-2256MEDIUM Encoded directory traversal vulnerability in phpPgAdmin 3.1 to 3.5.3 allows remote attackers to access arbitrary files via "%2e%2e%2f" (encoded dot dot) sequences in the formLangua | Jul 13, 2005 | 5.0 | 24 | NO | YES |
CVE-2025-60798MEDIUM phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in display.php at line 396. The application passes user-controlled input from $_REQUEST['query'] directly to th | Nov 20, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-60797MEDIUM phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in dataexport.php at line 118. The application directly executes user-supplied SQL queries from the $_REQUEST[' | Nov 20, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-60799MEDIUM phpPgAdmin 7.13.0 and earlier contains an incorrect access control vulnerability in sql.php at lines 68-76. The application allows unauthorized manipulation of session variables by | Nov 20, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-60796MEDIUM phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting (XSS) vulnerabilities across various components. User-supplied input from $_REQUEST parameters is reflected in | Nov 20, 2025 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phppgadmin.
Media articles that mention a CVE ID that affects a product developed by Phppgadmin — matched by CVE ID, not by vendor name.