Browse all 3 CVE security advisories affecting phpMyAdmin. AI-powered Chinese analysis, POCs, and references for each vulnerability.
phpMyAdmin serves as a web-based interface for managing MySQL and MariaDB databases, enabling administrators to perform administrative tasks through a browser. Historically, it has been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from improper input validation and session management issues. The application's widespread deployment and complex codebase have made it a frequent target for attackers. While recent versions have improved security practices, the presence of three active CVEs underscores ongoing risks. Notable incidents include past RCE flaws in import functionality and XSS vulnerabilities in various parameters, highlighting the importance of timely updates and proper configuration to mitigate potential exploitation.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-24530 | phpMyAdmin 跨站脚本漏洞 — phpMyAdmin CWE-79 | 6.4 | Medium | 2025-01-23 |
| CVE-2025-24529 | phpMyAdmin 跨站脚本漏洞 — phpMyAdmin CWE-79 | 6.4 | Medium | 2025-01-23 |
| CVE-2022-0813 | PhpMyAdmin exposure of sensitive information — phpMyAdmin CWE-200 | 5.3 | Medium | 2022-03-09 |
This page lists every published CVE security advisory associated with phpMyAdmin. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.