phpPgAdmin is a single, focused web-based administration interface for PostgreSQL databases that has attracted a recurrent pattern of critical-severity vulnerabilities across its application layer. The exposure concentrates on input-handling and access-control weaknesses including cross-site scripting, SQL injection, cross-site request forgery, untrusted deserialization, and improper access controls, reflecting the authentication and data-manipulation demands of a database administration tool. Defenders should treat this project's advisories as high-priority given the severity tendency and the privileged access such tools command; current severity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phppgadmin Project over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2865HIGH Cross-site scripting (XSS) vulnerability in sqledit.php in phpPgAdmin 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the server parameter. | May 25, 2007 | 9.3 | 39 | NO | YES |
CVE-2007-5728MEDIUM Cross-site scripting (XSS) vulnerability in phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, allows remote attackers to inject arbitrary web script or HTML via certain input available | Oct 30, 2007 | 4.3 | 34 | NO | YES |
CVE-2008-5587MEDIUM Directory traversal vulnerability in libraries/lib.inc.php in phpPgAdmin 4.2.1 and earlier, when register_globals is enabled, allows remote attackers to read arbitrary files via a | Dec 16, 2008 | 4.3 | 33 | NO | YES |
CVE-2019-10784CRITICAL phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area, "database.php" does not verif | Feb 4, 2020 | 9.6 | 31 | NO | NO |
CVE-2023-40619CRITICAL phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is directly passed to the PHP | Sep 20, 2023 | 9.8 | 27 | NO | NO |
CVE-2005-2256MEDIUM Encoded directory traversal vulnerability in phpPgAdmin 3.1 to 3.5.3 allows remote attackers to access arbitrary files via "%2e%2e%2f" (encoded dot dot) sequences in the formLangua | Jul 13, 2005 | 5.0 | 24 | NO | YES |
CVE-2025-60798MEDIUM phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in display.php at line 396. The application passes user-controlled input from $_REQUEST['query'] directly to th | Nov 20, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-60797MEDIUM phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in dataexport.php at line 118. The application directly executes user-supplied SQL queries from the $_REQUEST[' | Nov 20, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-60799MEDIUM phpPgAdmin 7.13.0 and earlier contains an incorrect access control vulnerability in sql.php at lines 68-76. The application allows unauthorized manipulation of session variables by | Nov 20, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-60796MEDIUM phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting (XSS) vulnerabilities across various components. User-supplied input from $_REQUEST parameters is reflected in | Nov 20, 2025 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phppgadmin Project.
Media articles that mention a CVE ID that affects a product developed by Phppgadmin Project — matched by CVE ID, not by vendor name.