Debian Phpmyadmin vulnerabilities
253 known vulnerabilities affecting debian/phpmyadmin.
Total CVEs
253
CISA KEV
1
actively exploited
Public exploits
34
Exploited in wild
3
Severity breakdown
CRITICAL18HIGH27MEDIUM95LOW113
Vulnerabilities
Page 6 of 13
CVE-2016-6622P4MEDIUMCVSS 5.9fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6622 [MEDIUM] CVE-2016-6622: phpmyadmin - An issue was discovered in phpMyAdmin. An unauthenticated user is able to execut...
An issue was discovered in phpMyAdmin. An unauthenticated user is able to execute a denial-of-service (DoS) attack by forcing persistent connections when phpMyAdmin is running with $cfg['AllowArbitraryServer']=true. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Scope: local
bookworm:
debian
CVE-2016-9850P4LOWCVSS 5.3fixed in phpmyadmin 4:4.6.5.1-1 (bookworm)2016
CVE-2016-9850 [MEDIUM] CVE-2016-9850: phpmyadmin - An issue was discovered in phpMyAdmin. Username matching for the allow/deny rule...
An issue was discovered in phpMyAdmin. Username matching for the allow/deny rules may result in wrong matches and detection of the username in the rule due to non-constant execution time. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
Scope: local
bookworm: resolved (fixed in 4:4.6.5.
debian
CVE-2020-10803P4MEDIUMCVSS 5.4fixed in phpmyadmin 4:4.9.5+dfsg1-1 (bookworm)2020
CVE-2020-10803 [MEDIUM] CVE-2020-10803: phpmyadmin - In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerabili...
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into certain database tables, which when retriev
debian
CVE-2011-2719P4LOWCVSS 6.4fixed in phpmyadmin 4:3.4.3.2-1 (bookworm)2011
CVE-2011-2719 [MEDIUM] CVE-2011-2719: phpmyadmin - libraries/auth/swekey/swekey.auth.lib.php in phpMyAdmin 3.x before 3.3.10.3 and ...
libraries/auth/swekey/swekey.auth.lib.php in phpMyAdmin 3.x before 3.3.10.3 and 3.4.x before 3.4.3.2 does not properly manage sessions associated with Swekey authentication, which allows remote attackers to modify the SESSION superglobal array, other superglobal arrays, and certain swekey.auth.lib.php local variables via a crafted query string, a related issue to
debian
CVE-2016-2562P4LOWCVSS 6.8fixed in phpmyadmin 4:4.5.5.1-1 (bookworm)2016
CVE-2016-2562 [MEDIUM] CVE-2016-2562: phpmyadmin - The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before ...
The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to spoof these servers and obtain sensitive information via a crafted certificate.
Scope: local
bookworm: resolved (fixed in 4:4.5.5.1-1)
bullseye: resolved (fixed in 4
debian
CVE-2016-6632P4MEDIUMCVSS 5.9fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6632 [MEDIUM] CVE-2016-6632: phpmyadmin - An issue was discovered in phpMyAdmin where, under certain conditions, phpMyAdmi...
An issue was discovered in phpMyAdmin where, under certain conditions, phpMyAdmin may not delete temporary files during the import of ESRI files. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Scope: local
bookworm: resolved (fixed in 4:4.6.4+dfsg1-1)
bullseye: resolved (fixed in 4:4.
debian
CVE-2016-6628P4MEDIUMCVSS 6.3fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6628 [MEDIUM] CVE-2016-6628: phpmyadmin - An issue was discovered in phpMyAdmin. An attacker may be able to trigger a user...
An issue was discovered in phpMyAdmin. An attacker may be able to trigger a user to download a specially crafted malicious SVG file. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Scope: local
bookworm: resolved (fixed in 4:4.6.4+dfsg1-1)
bullseye: resolved (fixed in 4:4.6.4+dfsg1-1)
debian
CVE-2025-24529P4MEDIUMCVSS 6.4fixed in phpmyadmin 4:5.2.1+dfsg-1+deb12u1 (bookworm)2025
CVE-2025-24529 [MEDIUM] CVE-2025-24529: phpmyadmin - An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has...
An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the Insert tab.
Scope: local
bookworm: resolved (fixed in 4:5.2.1+dfsg-1+deb12u1)
bullseye: resolved (fixed in 4:5.0.4+dfsg2-2+deb11u2)
forky: resolved (fixed in 4:5.2.2-really5.2.2+20250121+dfsg-1)
sid: resolved (fixed in 4:5.2.2-really5.2.2+20250121+dfsg-1)
tr
debian
CVE-2016-9847P4LOWCVSS 5.3fixed in phpmyadmin 4:4.6.5.1-1 (bookworm)2016
CVE-2016-9847 [MEDIUM] CVE-2016-9847: phpmyadmin - An issue was discovered in phpMyAdmin. When the user does not specify a blowfish...
An issue was discovered in phpMyAdmin. When the user does not specify a blowfish_secret key for encrypting cookies, phpMyAdmin generates one at runtime. A vulnerability was reported where the way this value is created uses a weak algorithm. This could allow an attacker to determine the user's blowfish_secret and potentially decrypt their cookies. All 4.6.x versio
debian
CVE-2016-6613P4MEDIUMCVSS 5.3fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6613 [MEDIUM] CVE-2016-6613: phpmyadmin - An issue was discovered in phpMyAdmin. A user can specially craft a symlink on d...
An issue was discovered in phpMyAdmin. A user can specially craft a symlink on disk, to a file which phpMyAdmin is permitted to read but the user is not, which phpMyAdmin will then expose to the user. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Scope: local
bookworm: resolved (fixe
debian
CVE-2016-5701P4MEDIUMCVSS 6.1fixed in phpmyadmin 4:4.6.3-1 (bookworm)2016
CVE-2016-5701 [MEDIUM] CVE-2016-5701: phpmyadmin - setup/frames/index.inc.php in phpMyAdmin 4.0.10.x before 4.0.10.16, 4.4.15.x bef...
setup/frames/index.inc.php in phpMyAdmin 4.0.10.x before 4.0.10.16, 4.4.15.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to conduct BBCode injection attacks against HTTP sessions via a crafted URI.
Scope: local
bookworm: resolved (fixed in 4:4.6.3-1)
bullseye: resolved (fixed in 4:4.6.3-1)
forky: resolved (fixed in 4:4.6.3-1)
sid: resolved (fi
debian
CVE-2011-2718P4MEDIUMCVSS 6.0fixed in phpmyadmin 4:3.4.3.2-1 (bookworm)2011
CVE-2011-2718 [MEDIUM] CVE-2011-2718: phpmyadmin - Multiple directory traversal vulnerabilities in the relational schema implementa...
Multiple directory traversal vulnerabilities in the relational schema implementation in phpMyAdmin 3.4.x before 3.4.3.2 allow remote authenticated users to include and execute arbitrary local files via directory traversal sequences in an export type field, related to (1) libraries/schema/User_Schema.class.php and (2) schema_export.php.
Scope: local
bookworm: reso
debian
CVE-2016-6615P4MEDIUMCVSS 6.1fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6615 [MEDIUM] CVE-2016-6615: phpmyadmin - XSS issues were discovered in phpMyAdmin. This affects navigation pane and datab...
XSS issues were discovered in phpMyAdmin. This affects navigation pane and database/table hiding feature (a specially-crafted database name can be used to trigger an XSS attack); the "Tracking" feature (a specially-crafted query can be used to trigger an XSS attack); and GIS visualization feature. All 4.6.x versions (prior to 4.6.4) and 4.4.x versions (prior to 4
debian
CVE-2016-6607P4MEDIUMCVSS 6.1fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6607 [MEDIUM] CVE-2016-6607: phpmyadmin - XSS issues were discovered in phpMyAdmin. This affects Zoom search (specially cr...
XSS issues were discovered in phpMyAdmin. This affects Zoom search (specially crafted column content can be used to trigger an XSS attack); GIS editor (certain fields in the graphical GIS editor are not properly escaped and can be used to trigger an XSS attack); Relation view; the following Transformations: Formatted, Imagelink, JPEG: Upload, RegexValidation, JPE
debian
CVE-2007-0203P4LOWCVSS 10.0fixed in phpmyadmin 4:2.9.1.1-2 (bookworm)2007
CVE-2007-0203 [CRITICAL] CVE-2007-0203: phpmyadmin - Multiple unspecified vulnerabilities in phpMyAdmin before 2.9.2-rc1 have unknown...
Multiple unspecified vulnerabilities in phpMyAdmin before 2.9.2-rc1 have unknown impact and attack vectors.
Scope: local
bookworm: resolved (fixed in 4:2.9.1.1-2)
bullseye: resolved (fixed in 4:2.9.1.1-2)
forky: resolved (fixed in 4:2.9.1.1-2)
sid: resolved (fixed in 4:2.9.1.1-2)
trixie: resolved (fixed in 4:2.9.1.1-2)
debian
CVE-2015-3902P4LOWCVSS 6.8fixed in phpmyadmin 4:4.4.6.1-1 (bookworm)2015
CVE-2015-3902 [MEDIUM] CVE-2015-3902: phpmyadmin - Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process ...
Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.
Scope: local
bookworm: resolved (fixed in 4:4.4.6.1-1)
bu
debian
CVE-2018-19970P4MEDIUMCVSS 6.1fixed in phpmyadmin 4:4.9.1+dfsg1-2 (bookworm)2018
CVE-2018-19970 [MEDIUM] CVE-2018-19970: phpmyadmin - In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tre...
In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name.
Scope: local
bookworm: resolved (fixed in 4:4.9.1+dfsg1-2)
bullseye: resolved (fixed in 4:4.9.1+dfsg1-2)
forky: resolved (fixed in 4:4.9.1+dfsg1-2)
sid: resolved (fixed in 4:4.9.1+dfsg1-2)
tr
debian
CVE-2020-26934P4MEDIUMCVSS 6.1fixed in phpmyadmin 4:4.9.7+dfsg1-1 (bookworm)2020
CVE-2020-26934 [MEDIUM] CVE-2020-26934: phpmyadmin - phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformati...
phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.
Scope: local
bookworm: resolved (fixed in 4:4.9.7+dfsg1-1)
bullseye: resolved (fixed in 4:4.9.7+dfsg1-1)
forky: resolved (fixed in 4:4.9.7+dfsg1-1)
sid: resolved (fixed in 4:4.9.7+dfsg1-1)
trixie: resolved (fixed in 4:4.9.7+dfsg1-1)
debian
CVE-2016-9857P4LOWCVSS 6.1fixed in phpmyadmin 4:4.6.5.1-1 (bookworm)2016
CVE-2016-9857 [MEDIUM] CVE-2016-9857: phpmyadmin - An issue was discovered in phpMyAdmin. XSS is possible because of a weakness in ...
An issue was discovered in phpMyAdmin. XSS is possible because of a weakness in a regular expression used in some JavaScript processing. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
Scope: local
bookworm: resolved (fixed in 4:4.6.5.1-1)
bullseye: resolved (fixed in 4:4.6.5.1-1)
fork
debian
CVE-2016-6608P4MEDIUMCVSS 6.1fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6608 [MEDIUM] CVE-2016-6608: phpmyadmin - XSS issues were discovered in phpMyAdmin. This affects the database privilege ch...
XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the "Remove partitioning" functionality. Specially crafted database names can trigger the XSS attack. All 4.6.x versions (prior to 4.6.4) are affected.
Scope: local
bookworm: resolved (fixed in 4:4.6.4+dfsg1-1)
bullseye: resolved (fixed in 4:4.6.4+dfsg1-1)
forky: resolved (fix
debian