Vrana/adminer
8 CVEs tracked. 1 of them are in CISA KEV.
This hub aggregates every CVE we track for Vrana/adminer, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Vrana/adminer CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 1 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 1 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 8 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High5
- Medium1
Latest CVEs
The 8 most recently published vulnerabilities affecting Vrana/adminer.
- CVE-2026-25892Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint7.5
- CVE-2025-43960Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. ...8.6
- GHSA-97h7-mf38-g9mfAdminer file disclosure vulnerability—
- CVE-2021-43008Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by requesting the Adminer to connect to a...7.5
- CVE-2021-29625XSS in doc_link7.5
- CVE-2021-21311SSRF in adminer7.2
- CVE-2020-35572Adminer through 4.7.8 allows XSS via the history parameter to the default URI.6.1
- CVE-2018-7667Adminer through 4.3.1 has SSRF via the server parameter.9.8
Product grouping is registry-driven, with AI assist and human review. How it works