Phpredisadmin is a web-based administration interface for Redis key-value stores, presenting a focused attack surface centered on a single widely used management tool. Its vulnerability footprint clusters around web-application input handling and session-management weaknesses, including cross-site request forgery, cross-site scripting, improper authorization, and string-comparison errors that are characteristic of PHP web interfaces exposed to administrative networks. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpredisadmin Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-4259CRITICAL A vulnerability was found in phpRedisAdmin up to 1.16.1. It has been classified as problematic. This affects the function authHttpDigest of the file includes/login.inc.php. The man | Dec 19, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-4268HIGH A vulnerability, which was classified as problematic, was found in phpRedisAdmin up to 1.17.3. This affects an unknown part. The manipulation leads to cross-site request forgery. I | Dec 21, 2022 | 8.8 | 27 | NO | NO |
CVE-2020-27163MEDIUM phpRedisAdmin before 1.13.2 allows XSS via the login.php username parameter. | Oct 16, 2020 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpredisadmin Project.
Media articles that mention a CVE ID that affects a product developed by Phpredisadmin Project — matched by CVE ID, not by vendor name.