Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

vrana — Vulnerabilities & Security Advisories 14

Browse all 14 CVE security advisories affecting vrana. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Vrana is a web application firewall primarily used to protect web applications from various attacks. Historically, it has been associated with vulnerabilities including remote code execution, cross-site scripting, and privilege escalation. The product has recorded three CVEs, highlighting potential security flaws in its implementation. While no major public security incidents have been widely documented, the presence of CVEs indicates that the software has had vulnerabilities requiring patches. Organizations implementing Vrana should ensure regular updates and proper configuration to mitigate potential risks. The tool's core function remains defense against web-based threats, though its own security history suggests vigilance is necessary.

Top products by vrana: adminer
CVE ID Title CVSS Severity Published
CVE-2026-56706 Adminer before 5.4.3 CSRF Token Secret Recovery via XOR Masking — adminer CWE-330 6.8 Medium 2026-08-25
CVE-2026-56705 Adminer before 5.4.3 Remote Code Execution via MSSQL PDO DSN Injection — adminer CWE-73 9.8 Critical 2026-08-25
CVE-2026-56704 Adminer before 5.4.3 Cross-Site Scripting via MySQL Version String — adminer CWE-79 6.1 Medium 2026-08-25
CVE-2026-56703 Adminer before 5.4.3 Remote Code Execution via SQLite VACUUM INTO — adminer CWE-94 7.2 High 2026-08-25
CVE-2026-34968 Adminer before 5.4.3 Arbitrary File Deletion via SQLite Drop — adminer CWE-22 8.1 High 2026-08-25
CVE-2026-56702 Adminer before 5.4.3 Unrestricted File Upload via AdminerFileUpload — adminer CWE-434 8.8 High 2026-08-25
CVE-2026-34967 Adminer sql-log Plugin 5.3.0 through 5.4.2 Arbitrary File Write — adminer CWE-73 5.4 Medium 2026-08-25
CVE-2026-34964 Adminer before 5.5.0 SSRF via PDO DSN Injection — adminer CWE-918 5.8 Medium 2026-08-25
CVE-2026-34959 Adminer before 5.5.0 Open Redirect via X-Forwarded-Prefix — adminer CWE-20 4.7 Medium 2026-08-25
CVE-2026-16434 Adminer before 5.5.1 X-Forwarded-Prefix Backslash Bypass — adminer CWE-20 2.3 Low 2026-08-25
CVE-2026-63771 Adminer < 5.4.3 Cookie Injection via X-Forwarded-Prefix Header — adminer CWE-113 7.1 High 2026-07-20
CVE-2026-25892 Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint — adminer CWE-20 7.5 High 2026-02-09
CVE-2021-29625 XSS in doc_link — adminer CWE-79 7.5 High 2021-05-19
CVE-2021-21311 SSRF in adminer — adminer CWE-918 7.2 High 2021-02-11

This page lists every published CVE security advisory associated with vrana. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.