ZeroHour

Vulnerabilities

11 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-25892
Adminer is open-source database management software.

Adminer is open-source database management software. Adminer v5.4.1 and earlier has a version check mechanism where adminer.org sends signed version info via JavaScript postMessage, which the browser then POSTs to ?script=version. This endpoint lacks origin validation and accepts POST data from any source. An attacker can POST version[] parameter which PHP converts to an array. On next page load, openssl_verify() receives this array instead of string and throws TypeError, returning HTTP 500 to all users. Upgrade to Adminer 5.4.2.

NVD description · AI analysis pending
7.52% PoC
  • adminer adminer
CVE-2025-43960
Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), lead

Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. Remote, unauthenticated attackers can trigger this by sending a malicious serialized object, which forces excessive memory usage, rendering Adminer’s interface unresponsive and causing a server-level DoS. While the server may recover after several minutes, multiple simultaneous requests can cause a complete crash requiring manual intervention.

NVD description · AI analysis pending
8.6<1% PoC
  • adminer adminer
CVE-2023-45196
+1 in the same advisory: …45195
Adminer and AdminerEvo allow an unauthenticated remote attacker to cause a denial of service by connecting to an attacker-controlled service that responds with

Adminer and AdminerEvo allow an unauthenticated remote attacker to cause a denial of service by connecting to an attacker-controlled service that responds with HTTP redirects. The denial of service is subject to PHP configuration limits. Adminer is no longer supported, but this issue was fixed in AdminerEvo version 4.8.4.

NVD description · AI analysis pending
6.9<1%
  • adminerevo adminerevo
CVE-2023-45197
The file upload plugin in Adminer and AdminerEvo allows an attacker to upload a file with a table name of “..” to the root of the Adminer directory.

The file upload plugin in Adminer and AdminerEvo allows an attacker to upload a file with a table name of “..” to the root of the Adminer directory. The attacker can effectively guess the name of the uploaded file and execute it. Adminer is no longer supported, but this issue was fixed in AdminerEvo version 4.8.3.

NVD description · AI analysis pending
9.2<1%
  • adminerevo adminerevo
CVE-2017-20066
A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic.

A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
7.8<1% PoC
  • adminer login project adminer login
CVE-2021-43008
Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by r

Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by requesting the Adminer to connect to a remote MySQL database.

NVD description · AI analysis pending
7.514% PoC ×2
  • adminer adminer
  • adminer debian linux
CVE-2021-29625
Adminer is open-source database management software.

Adminer is open-source database management software. A cross-site scripting vulnerability in Adminer versions 4.6.1 to 4.8.0 affects users of MySQL, MariaDB, PgSQL and SQLite. XSS is in most cases prevented by strict CSP in all modern browsers. The only exception is when Adminer is using a `pdo_` extension to communicate with the database (it is used if the native extensions are not enabled). In browsers without CSP, Adminer versions 4.6.1 to 4.8.0 are affected. The vulnerability is patched in version 4.8.1. As workarounds, one can use a browser supporting strict CSP or enable the native PHP extensions (e.g. `mysqli`) or disable displaying PHP errors (`display_errors`).

NVD description · AI analysis pending
6.110% PoC
  • adminer adminer
CVE-2021-21311
Server-Side Request Forgery in Adminer Database Management Tool (CVE-2021-21311)

Adminer, a popular single-file PHP database management tool, contains a server-side request forgery vulnerability (CWE-918) in versions 4.0.0 through before 4.7.9 when the deployment bundles all database drivers, such as the standard adminer.php file. An unauthenticated remote attacker can influence the database server address that Adminer connects to, causing the server-side PHP process to issue requests to attacker-chosen internal or external hosts and ports. This can be used to enumerate internal services and, as with other recently exploited SSRF flaws (e.g., the Pandoc attacks against AWS IMDS), to steal cloud instance metadata credentials. Anyone running an affected version, whether standalone or via the Debian adminer package, is exposed. The flaw has an EPSS of 90.5% and was added to CISA's Known Exploited Vulnerabilities catalog on 2025-09-29, confirming active exploitation in the wild.

Do: Upgrade Adminer to version 4.7.9 or later; on Debian, install the current security update for the adminer package. If upgrading is not immediately possible, restrict access to adminer.php (IP allowlisting, authentication, or removing it from the web root) and review logs for connections from the web server to internal services or cloud metadata endpoints such as 169.254.169.254. As a KEV entry, US federal agencies must apply the required mitigations or discontinue use per BOD 22-01 guidance.

7.290% KEV PoC
  • Adminer (standalone deployments bundling all drivers, e.g. the standard adminer.php) 4.0.0 through before 4.7.9
  • Debian Linux (adminer package) affected when the packaged Adminer is version 4.0.0 through before 4.7.9
largeon the order of tens of thousands of internet-exposed Adminer instances (total deployments likely higher)
CVE-2020-35572
Adminer through 4.7.8 allows XSS via the history parameter to the default URI.

Adminer through 4.7.8 allows XSS via the history parameter to the default URI.

NVD description · AI analysis pending
6.12% PoC
  • adminer adminer
CVE-2018-7667
Adminer through 4.3.1 has SSRF via the server parameter.

Adminer through 4.3.1 has SSRF via the server parameter.

NVD description · AI analysis pending
9.84% PoC
  • adminer adminer