Adminer
2 CVEs tracked since 2021. Since Feb 2021, 1 of them reached CISA KEV.
Adminer CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2021-02 | 2 | 1 |
Products
The products that kept showing up in Adminer's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 11 most recently published vulnerabilities affecting Adminer.
- CVE-2026-15686Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability7.2
- CVE-2026-25892Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint7.5
- CVE-2025-43960Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. ...8.6
- CVE-2023-45195Adminer and AdminerEvo SSRF5.3
- CVE-2023-45196Adminer and AdminerEvo denial of service via HTTP redirect7.5
- CVE-2023-45197Adminer and AdminerEvo vulnerable to directory traversal and file upload9.8
- CVE-2021-43008Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by requesting the Adminer to connect to a...7.5
- CVE-2021-29625XSS in doc_link7.5
- CVE-2021-21311SSRF in adminer7.2
- CVE-2020-35572Adminer through 4.7.8 allows XSS via the history parameter to the default URI.6.1
- CVE-2018-7667Adminer through 4.3.1 has SSRF via the server parameter.9.8
The record
- Peak rank
- #154 in Feb 2021
- Busiest month shown
- Feb 2021, 2 CVEs
- Months with a KEV entry
- 1 since Feb 2021
- Monthly snapshots
- 1 since 2021