Information on source package adminer

Available versions

ReleaseVersion
bookworm4.8.1-1
trixie5.2.1+dfsg-1
forky6.0.1-1
sid6.0.1-1

Open issues

BugbookwormtrixieforkysidDescription
CVE-2026-63771vulnerablevulnerable (no DSA)fixedfixedAdminer before 5.4.3 contains a cookie injection vulnerability that al ...
CVE-2026-56706vulnerablevulnerablefixedfixedAdminer before 5.4.3 uses a CSRF token scheme that transmits both the ...
CVE-2026-56705vulnerablevulnerablefixedfixedAdminer before 5.4.3 fails to sanitize the server field before constru ...
CVE-2026-56704vulnerablevulnerablefixedfixedAdminer before 5.4.3 inserts unsanitized database server version strin ...
CVE-2026-56703vulnerablevulnerablefixedfixedAdminer before 5.4.3 contains a remote code execution vulnerability in ...
CVE-2026-56702vulnerablevulnerablefixedfixedAdminer versions before 5.4.3 contain an unrestricted file upload vuln ...
CVE-2026-34968vulnerablevulnerablefixedfixedAdminer before 5.4.3 contains an arbitrary file deletion vulnerability ...
CVE-2026-34967vulnerablevulnerablefixedfixedAdminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled c ...
CVE-2026-34964vulnerablevulnerablefixedfixedAdminer before 5.5.0 contains a server-side request forgery vulnerabil ...
CVE-2026-34959vulnerablevulnerablefixedfixedAdminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Pr ...
CVE-2026-16434vulnerablevulnerablefixedfixedAdminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fi ...
CVE-2026-15686vulnerablevulnerable (no DSA)fixedfixedAdminer multi_query Incorrect Check of Function Return Value Remote Co ...
CVE-2023-45196vulnerable (no DSA)fixedfixedfixedAdminer and AdminerEvo allow an unauthenticated remote attacker to cau ...
CVE-2023-45195vulnerable (no DSA)fixedfixedfixedAdminer and AdminerEvo are vulnerable to SSRF via database connection ...

Open unimportant issues

BugbookwormtrixieforkysidDescription
CVE-2025-43960vulnerablevulnerablevulnerablevulnerableAdminer 4.8.1, when using Monolog for logging, allows a Denial of Serv ...

Resolved issues

BugDescription
CVE-2026-25892Adminer is open-source database management software. Adminer v5.4.1 an ...
CVE-2021-43008Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in ...
CVE-2021-29625Adminer is open-source database management software. A cross-site scri ...
CVE-2021-21311Adminer is an open-source database management in a single PHP file. In ...
CVE-2020-35572Adminer through 4.7.8 allows XSS via the history parameter to the defa ...
CVE-2018-7667Adminer through 4.3.1 has SSRF via the server parameter.

Security announcements

DSA / DLADescription
DLA-3002-1adminer - security update
DLA-2580-1adminer - security update
DLA-1311-1adminer - security update

Search for package or bug name: Reporting problems