Debian Phpmyadmin vulnerabilities
253 known vulnerabilities affecting debian/phpmyadmin.
Total CVEs
253
CISA KEV
1
actively exploited
Public exploits
34
Exploited in wild
3
Severity breakdown
CRITICAL18HIGH27MEDIUM95LOW113
Vulnerabilities
Page 8 of 13
CVE-2016-6626P4MEDIUMCVSS 5.4fixed in phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)2016
CVE-2016-6626 [MEDIUM] CVE-2016-6626: phpmyadmin - An issue was discovered in phpMyAdmin. An attacker could redirect a user to a ma...
An issue was discovered in phpMyAdmin. An attacker could redirect a user to a malicious web page. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Scope: local
bookworm: resolved (fixed in 4:4.6.4+dfsg1-1)
bullseye: resolved (fixed in 4:4.6.4+dfsg1-1)
forky: resolved (fixed in 4:4.6.4+d
debian
CVE-2023-25727P4MEDIUMCVSS 5.4fixed in phpmyadmin 4:5.2.1+dfsg-1 (bookworm)2023
CVE-2023-25727 [MEDIUM] CVE-2023-25727: phpmyadmin - In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trig...
In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.
Scope: local
bookworm: resolved (fixed in 4:5.2.1+dfsg-1)
bullseye: resolved (fixed in 4:5.0.4+dfsg2-2+deb11u2)
forky: resolved (fixed in 4:5.2.1+dfsg-1)
sid: resolved (fixed in 4:5.2.1+dfsg-1)
trixie: res
debian
CVE-2011-0986P4LOWCVSS 5.0fixed in phpmyadmin 4:3.3.9.2-1 (bookworm)2011
CVE-2011-0986 [MEDIUM] CVE-2011-0986: phpmyadmin - phpMyAdmin 2.11.x before 2.11.11.2, and 3.3.x before 3.3.9.1, does not properly ...
phpMyAdmin 2.11.x before 2.11.11.2, and 3.3.x before 3.3.9.1, does not properly handle the absence of the (1) README, (2) ChangeLog, and (3) LICENSE files, which allows remote attackers to obtain the installation path via a direct request for a nonexistent file.
Scope: local
bookworm: resolved (fixed in 4:3.3.9.2-1)
bullseye: resolved (fixed in 4:3.3.9.2-1)
forky
debian
CVE-2013-5029P4MEDIUMCVSS 4.3fixed in phpmyadmin 4:4.0.5-1 (bookworm)2013
CVE-2013-5029 [MEDIUM] CVE-2013-5029: phpmyadmin - phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to bypass the cl...
phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to bypass the clickjacking protection mechanism via certain vectors related to Header.class.php.
Scope: local
bookworm: resolved (fixed in 4:4.0.5-1)
bullseye: resolved (fixed in 4:4.0.5-1)
forky: resolved (fixed in 4:4.0.5-1)
sid: resolved (fixed in 4:4.0.5-1)
trixie: resolved (fixed in 4:4.0.5-1)
debian
CVE-2008-3456P4LOWCVSS 6.4fixed in phpmyadmin 4:2.11.8~rc1-1 (bookworm)2008
CVE-2008-3456 [MEDIUM] CVE-2008-3456: phpmyadmin - phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using fram...
phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoofing or phishing activities via a cross-site framing attack.
Scope: local
bookworm: resolved (fixed in 4:2.11.8~rc1-1)
bullseye: resolved (fixed in 4:2.11.8~rc1-1)
forky: resolved (fixed
debian
CVE-2016-5097P4LOWCVSS 5.3fixed in phpmyadmin 4:4.6.2-1 (bookworm)2016
CVE-2016-5097 [MEDIUM] CVE-2016-5097: phpmyadmin - phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for ...
phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests or (2) server logs.
Scope: local
bookworm: resolved (fixed in 4:4.6.2-1)
bullseye: resolved (fixed in 4:4.6.2-1)
forky: resolved (fixed in 4:4.6.2
debian
CVE-2010-4481P4MEDIUMCVSS 5.0fixed in phpmyadmin 4:3.3.7-3 (bookworm)2010
CVE-2010-4481 [MEDIUM] CVE-2010-4481: phpmyadmin - phpMyAdmin before 3.4.0-beta1 allows remote attackers to bypass authentication a...
phpMyAdmin before 3.4.0-beta1 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to phpinfo.php, which calls the phpinfo function.
Scope: local
bookworm: resolved (fixed in 4:3.3.7-3)
bullseye: resolved (fixed in 4:3.3.7-3)
forky: resolved (fixed in 4:3.3.7-3)
sid: resolved (fixed in 4:3.3.7-3)
trixie: resolved
debian
CVE-2016-5731P4LOWCVSS 6.1fixed in phpmyadmin 4:4.6.3-1 (bookworm)2016
CVE-2016-5731 [MEDIUM] CVE-2016-5731: phpmyadmin - Cross-site scripting (XSS) vulnerability in examples/openid.php in phpMyAdmin 4....
Cross-site scripting (XSS) vulnerability in examples/openid.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to inject arbitrary web script or HTML via vectors involving an OpenID error message.
Scope: local
bookworm: resolved (fixed in 4:4.6.3-1)
bullseye: resolved (fixed in 4:4.6.3-1)
forky: resolve
debian
CVE-2016-5704P4MEDIUMCVSS 6.1fixed in phpmyadmin 4:4.6.3-1 (bookworm)2016
CVE-2016-5704 [MEDIUM] CVE-2016-5704: phpmyadmin - Cross-site scripting (XSS) vulnerability in the table-structure page in phpMyAdm...
Cross-site scripting (XSS) vulnerability in the table-structure page in phpMyAdmin 4.6.x before 4.6.3 allows remote attackers to inject arbitrary web script or HTML via vectors involving a comment.
Scope: local
bookworm: resolved (fixed in 4:4.6.3-1)
bullseye: resolved (fixed in 4:4.6.3-1)
forky: resolved (fixed in 4:4.6.3-1)
sid: resolved (fixed in 4:4.6.3-1)
tr
debian
CVE-2016-5732P4MEDIUMCVSS 6.1fixed in phpmyadmin 4:4.6.3-1 (bookworm)2016
CVE-2016-5732 [MEDIUM] CVE-2016-5732: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in the partition-range imple...
Multiple cross-site scripting (XSS) vulnerabilities in the partition-range implementation in templates/table/structure/display_partitions.phtml in the table-structure page in phpMyAdmin 4.6.x before 4.6.3 allow remote attackers to inject arbitrary web script or HTML via crafted table parameters.
Scope: local
bookworm: resolved (fixed in 4:4.6.3-1)
bullseye: resol
debian
CVE-2016-5705P4MEDIUMCVSS 6.1fixed in phpmyadmin 4:4.6.3-1 (bookworm)2016
CVE-2016-5705 [MEDIUM] CVE-2016-5705: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4...
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) server-privileges certificate data fields on the user privileges page, (2) an "invalid JSON" error message in the error console, (3) a database name in the central co
debian
CVE-2016-2561P4MEDIUMCVSS 5.4fixed in phpmyadmin 4:4.5.5.1-1 (bookworm)2016
CVE-2016-2561 [MEDIUM] CVE-2016-2561: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4...
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.5 and 4.5.x before 4.5.5.1 allow remote authenticated users to inject arbitrary web script or HTML via (1) normalization.php or (2) js/normalization.js in the database normalization page, (3) templates/database/structure/sortable_header.phtml in the database structure page, or (
debian
CVE-2013-4729P4MEDIUMCVSS 5.5fixed in phpmyadmin 4:4.0.4.1-1 (bookworm)2013
CVE-2013-4729 [MEDIUM] CVE-2013-4729: phpmyadmin - import.php in phpMyAdmin 4.x before 4.0.4.1 does not properly restrict the abili...
import.php in phpMyAdmin 4.x before 4.0.4.1 does not properly restrict the ability of input data to specify a file format, which allows remote authenticated users to modify the GLOBALS superglobal array, and consequently change the configuration, via a crafted request.
Scope: local
bookworm: resolved (fixed in 4:4.0.4.1-1)
bullseye: resolved (fixed in 4:4.0.4.1-1
debian
CVE-2004-1148P4MEDIUMCVSS 5.0fixed in phpmyadmin 2:2.6.1-rc1-1 (bookworm)2004
CVE-2004-1148 [MEDIUM] CVE-2004-1148: phpmyadmin - phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows re...
phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter.
Scope: local
bookworm: resolved (fixed in 2:2.6.1-rc1-1)
bullseye: resolved (fixed in 2:2.6.1-rc1-1)
forky: resolved (fixed in 2:2.6.1-rc1-1)
sid: resolved (fixed in 2:2.6.1-rc1-1)
trixie: resolved (fixed in 2:2.6
debian
CVE-2025-3573P4MEDIUMCVSS 5.3fixed in kalkun 0.8.3.2-1 (forky)2025
CVE-2025-3573 [MEDIUM] CVE-2025-3573: civicrm - Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-...
Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder value. This value will populate a message via $.validator.messages in a user localizable dictionary.
Scope: local
bullseye: open
debian
CVE-2016-5099P4LOWCVSS 6.1fixed in phpmyadmin 4:4.6.2-1 (bookworm)2016
CVE-2016-5099 [MEDIUM] CVE-2016-5099: phpmyadmin - Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and...
Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web script or HTML via special characters that are mishandled during double URL decoding.
Scope: local
bookworm: resolved (fixed in 4:4.6.2-1)
bullseye: resolved (fixed in 4:4.6.2-1)
forky: resolved (fixed in 4:4.6.2-1)
s
debian
CVE-2016-2040P4MEDIUMCVSS 5.4fixed in phpmyadmin 4:4.5.4-1 (bookworm)2016
CVE-2016-2040 [MEDIUM] CVE-2016-2040: phpmyadmin - Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4...
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) table name, (2) SET value, (3) search query, or (4) hostname in a Location header.
Scope: local
bookworm: resolved (fixed in 4:4.5.4-1)
bullseye: r
debian
CVE-2018-7260P4MEDIUMCVSS 5.4fixed in phpmyadmin 4:4.9.1+dfsg1-2 (bookworm)2018
CVE-2018-7260 [MEDIUM] CVE-2018-7260: phpmyadmin - Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin...
Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin before 4.7.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Scope: local
bookworm: resolved (fixed in 4:4.9.1+dfsg1-2)
bullseye: resolved (fixed in 4:4.9.1+dfsg1-2)
forky: resolved (fixed in 4:4.9.1+dfsg1-2)
sid: resolved (fixed in 4:4.9.1
debian
CVE-2016-2045P4LOWCVSS 5.4fixed in phpmyadmin 4:4.5.4-1 (bookworm)2016
CVE-2016-2045 [MEDIUM] CVE-2016-2045: phpmyadmin - Cross-site scripting (XSS) vulnerability in the SQL editor in phpMyAdmin 4.5.x b...
Cross-site scripting (XSS) vulnerability in the SQL editor in phpMyAdmin 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a SQL query that triggers JSON data in a response.
Scope: local
bookworm: resolved (fixed in 4:4.5.4-1)
bullseye: resolved (fixed in 4:4.5.4-1)
forky: resolved (fixed in 4:4.5.4-1)
sid: resolved (
debian
CVE-2016-2044P4MEDIUMCVSS 5.3fixed in phpmyadmin 4:4.5.4-1 (bookworm)2016
CVE-2016-2044 [MEDIUM] CVE-2016-2044: phpmyadmin - libraries/sql-parser/autoload.php in the SQL parser in phpMyAdmin 4.5.x before 4...
libraries/sql-parser/autoload.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
Scope: local
bookworm: resolved (fixed in 4:4.5.4-1)
bullseye: resolved (fixed in 4:4.5.4-1)
forky: resolved (fixed in 4:4.5.4-1)
sid: resolved (fixed i
debian