Phppgadmin Project
Phppgadmin Project Phppgadmin: vulnerabilidades y CVE
Phppgadmin Project Phppgadmin tiene 7 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses4
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-60799 | Media (6.1) | 0.21% | — | 20 nov 2025 | phpPgAdmin 7.13.0 and earlier contains an incorrect access control vulnerability in sql.php at lines 68-76. The application allows unauthorized manipulation of session variables by accepting user-controlled parameters… |
| CVE-2025-60798 | Media (6.5) | 0.29% | — | 20 nov 2025 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in display.php at line 396. The application passes user-controlled input from $_REQUEST['query'] directly to the browseQuery function without proper… |
| CVE-2025-60797 | Media (6.5) | 0.27% | — | 20 nov 2025 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in dataexport.php at line 118. The application directly executes user-supplied SQL queries from the $_REQUEST['query'] parameter without any… |
| CVE-2025-60796 | Media (6.1) | 0.23% | — | 20 nov 2025 | phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting (XSS) vulnerabilities across various components. User-supplied input from $_REQUEST parameters is reflected in HTML output without proper encoding or… |
| CVE-2023-40619 | Crítica (9.8) | 1.3% | — | 20 sept 2023 | phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is directly passed to the PHP 'unserialize()' function in multiple… |
| CVE-2019-10784 | Crítica (9.6) | 3.6% | — | 4 feb 2020 | phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area, "database.php" does not verify the source of an HTTP request. This… |
| CVE-2012-1600 | Media (4.3) | 2.7% | — | 14 may 2014 | Multiple cross-site scripting (XSS) vulnerabilities in functions.php in phpPgAdmin before 5.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) type of a function. |