Debian Adminer vulnerabilities
9 known vulnerabilities affecting debian/adminer.
Total CVEs
9
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM3LOW2
Vulnerabilities
Page 1 of 1
CVE-2026-25892LOWCVSS 7.5PoC2026
CVE-2026-25892 [HIGH] CVE-2026-25892: adminer - Adminer is open-source database management software. Adminer v5.4.1 and earlier ...
Adminer is open-source database management software. Adminer v5.4.1 and earlier has a version check mechanism where adminer.org sends signed version info via JavaScript postMessage, which the browser then POSTs to ?script=version. This endpoint lacks origin validation and accepts POST data from any source. An attacker can POST version[] parameter which PHP converts
debian
CVE-2025-43960LOWCVSS 8.62025
CVE-2025-43960 [HIGH] CVE-2025-43960: adminer - Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memor...
Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. Remote, unauthenticated attackers can trigger this by sending a malicious serialized object, which forces excessive memory usage, rendering Adminer’s interface unresponsiv
debian
CVE-2023-45196MEDIUMCVSS 6.9fixed in adminer 4.8.1-4 (forky)2023
CVE-2023-45196 [MEDIUM] CVE-2023-45196: adminer - Adminer and AdminerEvo allow an unauthenticated remote attacker to cause a denia...
Adminer and AdminerEvo allow an unauthenticated remote attacker to cause a denial of service by connecting to an attacker-controlled service that responds with HTTP redirects. The denial of service is subject to PHP configuration limits. Adminer is no longer supported, but this issue was fixed in AdminerEvo version 4.8.4.
Scope: local
bookworm: open
bullseye: open
debian
CVE-2023-45195MEDIUMCVSS 6.9fixed in adminer 4.8.1-4 (forky)2023
CVE-2023-45195 [MEDIUM] CVE-2023-45195: adminer - Adminer and AdminerEvo are vulnerable to SSRF via database connection fields. Th...
Adminer and AdminerEvo are vulnerable to SSRF via database connection fields. This could allow an unauthenticated remote attacker to enumerate or access systems the attacker would not otherwise have access to. Adminer is no longer supported, but this issue was fixed in AdminerEvo version 4.8.4.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 4
debian
CVE-2021-43008HIGHCVSS 7.5fixed in adminer 4.6.3-1 (bookworm)2021
CVE-2021-43008 [HIGH] CVE-2021-43008: adminer - Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4....
Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by requesting the Adminer to connect to a remote MySQL database.
Scope: local
bookworm: resolved (fixed in 4.6.3-1)
bullseye: resolved (fixed in 4.6.3-1)
forky: resolved (fixed in 4.6.3-1)
sid: resolved (fixed in
debian
CVE-2021-29625HIGHCVSS 7.5PoCfixed in adminer 4.7.9-2 (bookworm)2021
CVE-2021-29625 [HIGH] CVE-2021-29625: adminer - Adminer is open-source database management software. A cross-site scripting vuln...
Adminer is open-source database management software. A cross-site scripting vulnerability in Adminer versions 4.6.1 to 4.8.0 affects users of MySQL, MariaDB, PgSQL and SQLite. XSS is in most cases prevented by strict CSP in all modern browsers. The only exception is when Adminer is using a `pdo_` extension to communicate with the database (it is used if the native e
debian
CVE-2021-21311HIGHCVSS 7.2KEVPoCfixed in adminer 4.7.9-1 (bookworm)2021
CVE-2021-21311 [HIGH] CVE-2021-21311: adminer - Adminer is an open-source database management in a single PHP file. In adminer f...
Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This is fixed in version 4.7.9.
Scope: local
bookworm: resolved (fixed in 4.7.9-1)
bullseye: resolved (fixed in 4.7.9
debian
CVE-2020-35572MEDIUMCVSS 6.1fixed in adminer 4.7.9-1 (bookworm)2020
CVE-2020-35572 [MEDIUM] CVE-2020-35572: adminer - Adminer through 4.7.8 allows XSS via the history parameter to the default URI.
Adminer through 4.7.8 allows XSS via the history parameter to the default URI.
Scope: local
bookworm: resolved (fixed in 4.7.9-1)
bullseye: resolved (fixed in 4.7.9-1)
forky: resolved (fixed in 4.7.9-1)
sid: resolved (fixed in 4.7.9-1)
trixie: resolved (fixed in 4.7.9-1)
debian
CVE-2018-7667CRITICALCVSS 9.8fixed in adminer 4.5.0-1 (bookworm)2018
CVE-2018-7667 [CRITICAL] CVE-2018-7667: adminer - Adminer through 4.3.1 has SSRF via the server parameter.
Adminer through 4.3.1 has SSRF via the server parameter.
Scope: local
bookworm: resolved (fixed in 4.5.0-1)
bullseye: resolved (fixed in 4.5.0-1)
forky: resolved (fixed in 4.5.0-1)
sid: resolved (fixed in 4.5.0-1)
trixie: resolved (fixed in 4.5.0-1)
debian