Phppgadmin
Vendor:
First CVE: Jun 27, 2001 · Active for 25 years
13
Total CVEs
More Total CVEs than 83% of tracked products
1.4
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 41% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Phppgadmin over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 27, 2001
25 years ago
Most Recent CVE
Nov 20, 2025
246 days ago
CVE Severity & Scoring
Phppgadmin13 CVEs
69%
15%
15%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (46.2%)
Unknown7 (53.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (46.2%)
High0 (0.0%)
Unknown7 (53.8%)
User Interaction
None3 (23.1%)
Unknown7 (53.8%)
Required3 (23.1%)
Privileges Required
Low2 (15.4%)
High0 (0.0%)
None4 (30.8%)
Unknown7 (53.8%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2865HIGH Cross-site scripting (XSS) vulnerability in sqledit.php in phpPgAdmin 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the server parameter. | May 25, 2007 | 9.3 | 39 | NO | YES |
CVE-2007-5728MEDIUM Cross-site scripting (XSS) vulnerability in phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, allows remote attackers to inject arbitrary web script or HTML via certain input available | Oct 30, 2007 | 4.3 | 34 | NO | YES |
CVE-2008-5587MEDIUM Directory traversal vulnerability in libraries/lib.inc.php in phpPgAdmin 4.2.1 and earlier, when register_globals is enabled, allows remote attackers to read arbitrary files via a | Dec 16, 2008 | 4.3 | 33 | NO | YES |
CVE-2019-10784CRITICAL phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area, "database.php" does not verif | Feb 4, 2020 | 9.6 | 31 | NO | NO |
CVE-2023-40619CRITICAL phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is directly passed to the PHP | Sep 20, 2023 | 9.8 | 27 | NO | NO |
CVE-2005-2256MEDIUM Encoded directory traversal vulnerability in phpPgAdmin 3.1 to 3.5.3 allows remote attackers to access arbitrary files via "%2e%2e%2f" (encoded dot dot) sequences in the formLangua | Jul 13, 2005 | 5.0 | 24 | NO | YES |
CVE-2025-60798MEDIUM phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in display.php at line 396. The application passes user-controlled input from $_REQUEST['query'] directly to th | Nov 20, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-60797MEDIUM phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in dataexport.php at line 118. The application directly executes user-supplied SQL queries from the $_REQUEST[' | Nov 20, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-60799MEDIUM phpPgAdmin 7.13.0 and earlier contains an incorrect access control vulnerability in sql.php at lines 68-76. The application allows unauthorized manipulation of session variables by | Nov 20, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-60796MEDIUM phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting (XSS) vulnerabilities across various components. User-supplied input from $_REQUEST parameters is reflected in | Nov 20, 2025 | 6.1 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
15.4% of CVEs· Bottom 1%
ExploitDB
4 CVEs
30.8% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Phppgadmin
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.0.2 | 1 | 4.3 | 2.7% | 0 | 0 |
| 5.0.1 | 2 | 4.3 | 2.6% | 0 | 0 |
| 5.0.0 | 1 | 4.3 | 2.5% | 0 | 0 |
| 5.0 | 1 | 4.3 | 2.7% | 0 | 0 |
| 4.2.3 | 1 | 4.3 | 2.5% | 0 | 0 |
| 4.2.2 | 1 | 4.3 | 2.5% | 0 | 0 |
| 4.2.1 | 1 | 4.3 | 2.5% | 0 | 0 |
| 4.1.1 | 4 | 5.5 | 9.0% | 0 | 3 |
| 3.5.3 | 4 | 4.5 | 8.7% | 0 | 3 |
| 3.5.2 | 3 | 4.3 | 10.0% | 0 | 2 |
| 3.5 | 3 | 4.3 | 10.0% | 0 | 2 |
| 3.4.1 | 3 | 4.5 | 6.7% | 0 | 2 |
| 3.4 | 2 | 4.7 | 3.6% | 0 | 1 |
| 3.3 | 2 | 4.7 | 3.6% | 0 | 1 |
| 3.2 | 2 | 4.7 | 3.6% | 0 | 1 |
| 3.1 | 3 | 4.5 | 6.7% | 0 | 2 |
| 2.2.1 | 3 | 5.4 | 7.1% | 0 | 1 |
| 2.2 | 3 | 5.4 | 7.1% | 0 | 1 |