Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2022-23808Cross-site Scripting in Phpmyadmin

Severity
6.1MEDIUMNVD
EPSS
48.8%
top 2.23%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJan 22
Latest updateJan 27

Description

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

debiandebian/phpmyadmin< phpmyadmin 4:5.1.3+dfsg1-1 (bookworm)
NVDphpmyadmin/phpmyadmin5.1.05.1.2
Packagistphpmyadmin/phpmyadmin5.1.05.1.2
Debianphpmyadmin/phpmyadmin< 4:5.1.3+dfsg1-1+2

Patches

🔴Vulnerability Details

4
OSV
Cross-site Scripting in phpmyadmin2022-01-28
GHSA
Cross-site Scripting in phpmyadmin2022-01-28
OSV
CVE-2022-23808: An issue was discovered in phpMyAdmin 52022-01-22
CVEList
CVE-2022-23808: An issue was discovered in phpMyAdmin 52022-01-22

💥Exploits & PoCs

1
Nuclei
phpMyAdmin < 5.1.2 - Cross-Site Scripting

📋Vendor Advisories

2
CISA ICS
Festo Didactic SE MES PC2026-01-27
Debian
CVE-2022-23808: phpmyadmin - An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject m...2022

🕵️Threat Intelligence

1
Greynoiseio
NoiseLetter January 2026