Search CVE reports


Toggle filters

1 – 10 of 264 results


CVE-2025-3573

Medium priority
Needs evaluation

Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder value. This value will populate a message...

4 affected packages

kalkun, civicrm, phpmyadmin, znuny

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kalkun Not in release Not in release Not in release
civicrm Not in release Needs evaluation Needs evaluation Needs evaluation
phpmyadmin Needs evaluation Needs evaluation Needs evaluation Needs evaluation
znuny Needs evaluation Not in release Not in release
Show less packages

CVE-2025-24530

Medium priority
Needs evaluation

An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the check tables feature. A crafted table or database name could be used for XSS.

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-24529

Medium priority
Needs evaluation

An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the Insert tab.

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-25727

Medium priority
Needs evaluation

In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-22452

Medium priority
Needs evaluation

SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-0813

Medium priority
Needs evaluation

PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section.

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-23808

Medium priority
Needs evaluation

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Needs evaluation Needs evaluation Not affected Not affected
Show less packages

CVE-2022-23807

Medium priority
Vulnerable

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Needs evaluation Needs evaluation Vulnerable Not affected
Show less packages

CVE-2021-21252

Medium priority
Vulnerable

The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package "jquery-validation". jquery-validation before version 1.19.3 contains one or more regular expressions that are...

3 affected packages

civicrm, otrs2, phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
civicrm Not in release Vulnerable Vulnerable Vulnerable
otrs2 Not in release Vulnerable Vulnerable Vulnerable
phpmyadmin Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2020-22278

Medium priority
Ignored

phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.

1 affected package

phpmyadmin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
phpmyadmin Not affected Not affected Not affected Not affected
Show less packages