Phppgadmin

Vendor:

First CVE: Jun 27, 2001 · Active for 25 years

13
Total CVEs
More Total CVEs than 83% of tracked products
1.4
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 41% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Phppgadmin over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 27, 2001
25 years ago
Most Recent CVE
Nov 20, 2025
246 days ago

CVE Severity & Scoring

Phppgadmin13 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (46.2%)
Unknown7 (53.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (46.2%)
High0 (0.0%)
Unknown7 (53.8%)
User Interaction
None3 (23.1%)
Unknown7 (53.8%)
Required3 (23.1%)
Privileges Required
Low2 (15.4%)
High0 (0.0%)
None4 (30.8%)
Unknown7 (53.8%)

Top CVEs

Signals from CVEs in this product scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Cross-site scripting (XSS) vulnerability in sqledit.php in phpPgAdmin 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the server parameter.
May 25, 20079.339NOYES
Cross-site scripting (XSS) vulnerability in phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, allows remote attackers to inject arbitrary web script or HTML via certain input available
Oct 30, 20074.334NOYES
Directory traversal vulnerability in libraries/lib.inc.php in phpPgAdmin 4.2.1 and earlier, when register_globals is enabled, allows remote attackers to read arbitrary files via a
Dec 16, 20084.333NOYES
phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area, "database.php" does not verif
Feb 4, 20209.631NONO
phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is directly passed to the PHP
Sep 20, 20239.827NONO
Encoded directory traversal vulnerability in phpPgAdmin 3.1 to 3.5.3 allows remote attackers to access arbitrary files via "%2e%2e%2f" (encoded dot dot) sequences in the formLangua
Jul 13, 20055.024NOYES
phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in display.php at line 396. The application passes user-controlled input from $_REQUEST['query'] directly to th
Nov 20, 20256.522NONO
phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in dataexport.php at line 118. The application directly executes user-supplied SQL queries from the $_REQUEST['
Nov 20, 20256.522NONO
phpPgAdmin 7.13.0 and earlier contains an incorrect access control vulnerability in sql.php at lines 68-76. The application allows unauthorized manipulation of session variables by
Nov 20, 20256.121NONO
phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting (XSS) vulnerabilities across various components. User-supplied input from $_REQUEST parameters is reflected in
Nov 20, 20256.121NONO

Exploit Exposure

Signals from CVEs in this product scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
15.4% of CVEs· Bottom 1%
ExploitDB
4 CVEs
30.8% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (13 CVEs).

Media Mentions

Signals from CVEs in this product scope (13 CVEs).

Top CNAs Publishing CVEs For Phppgadmin

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.0.214.32.7%00
5.0.124.32.6%00
5.0.014.32.5%00
5.014.32.7%00
4.2.314.32.5%00
4.2.214.32.5%00
4.2.114.32.5%00
4.1.145.59.0%03
3.5.344.58.7%03
3.5.234.310.0%02
3.534.310.0%02
3.4.134.56.7%02
3.424.73.6%01
3.324.73.6%01
3.224.73.6%01
3.134.56.7%02
2.2.135.47.1%01
2.235.47.1%01