Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Phppgadmin Project

First CVE: Jun 27, 2001Active for: 25 yearsTotal CVEs: 13

phpPgAdmin is a single, focused web-based administration interface for PostgreSQL databases that has attracted a recurrent pattern of critical-severity vulnerabilities across its application layer. The exposure concentrates on input-handling and access-control weaknesses including cross-site scripting, SQL injection, cross-site request forgery, untrusted deserialization, and improper access controls, reflecting the authentication and data-manipulation demands of a database administration tool. Defenders should treat this project's advisories as high-priority given the severity tendency and the privileged access such tools command; current severity and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 88% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Phppgadmin Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 27, 2001
25 years ago
Most Recent CVE
Nov 20, 2025
246 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2007-2865HIGH
Cross-site scripting (XSS) vulnerability in sqledit.php in phpPgAdmin 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the server parameter.
May 25, 20079.339NOYES
CVE-2007-5728MEDIUM
Cross-site scripting (XSS) vulnerability in phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, allows remote attackers to inject arbitrary web script or HTML via certain input available
Oct 30, 20074.334NOYES
CVE-2008-5587MEDIUM
Directory traversal vulnerability in libraries/lib.inc.php in phpPgAdmin 4.2.1 and earlier, when register_globals is enabled, allows remote attackers to read arbitrary files via a
Dec 16, 20084.333NOYES
CVE-2019-10784CRITICAL
phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area, "database.php" does not verif
Feb 4, 20209.631NONO
CVE-2023-40619CRITICAL
phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is directly passed to the PHP
Sep 20, 20239.827NONO
CVE-2005-2256MEDIUM
Encoded directory traversal vulnerability in phpPgAdmin 3.1 to 3.5.3 allows remote attackers to access arbitrary files via "%2e%2e%2f" (encoded dot dot) sequences in the formLangua
Jul 13, 20055.024NOYES
CVE-2025-60798MEDIUM
phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in display.php at line 396. The application passes user-controlled input from $_REQUEST['query'] directly to th
Nov 20, 20256.522NONO
CVE-2025-60797MEDIUM
phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in dataexport.php at line 118. The application directly executes user-supplied SQL queries from the $_REQUEST['
Nov 20, 20256.522NONO
CVE-2025-60799MEDIUM
phpPgAdmin 7.13.0 and earlier contains an incorrect access control vulnerability in sql.php at lines 68-76. The application allows unauthorized manipulation of session variables by
Nov 20, 20256.121NONO
CVE-2025-60796MEDIUM
phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting (XSS) vulnerabilities across various components. User-supplied input from $_REQUEST parameters is reflected in
Nov 20, 20256.121NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
69%
15%
15%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (46.2%)
Unknown7 (53.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (46.2%)
High0 (0.0%)
Unknown7 (53.8%)
User Interaction
None3 (23.1%)
Unknown7 (53.8%)
Required3 (23.1%)
Privileges Required
Low2 (15.4%)
High0 (0.0%)
None4 (30.8%)
Unknown7 (53.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
15.4% of CVEs· Bottom 1%
ExploitDB
4 CVEs
30.8% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Phppgadmin Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Phppgadmin Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Phppgadmin Project's Products

View all 3 CNAs →

Top CWEs