vrana/adminer
Database management in a single PHP file
Activity
- Latest release
- 1d ago
- Total releases
- 63
- Cadence
- ~14 days
- Last 12 months
- 9
Reach
- Stars
- 7.9k
Details
- License
- Apache-2.0 OR unknown
- First release
- Feb 07, 2015
| Version | Released | |
|---|---|---|
v6.1.0
minor
|
v6.1.0
minor
Changelog
Compare changes
|
|
v6.0.2
patch
|
v6.0.2
patch
Changelog
Compare changes
|
|
v6.0.1
patch
|
v6.0.1
patch
Changelog
Compare changes
|
|
v6.0.0
major
|
v6.0.0
major
Changelog
Compare changes
|
|
v5.5.1
patch
|
v5.5.1
patch
Changelog
Compare changes
|
|
v5.5.0
minor
| ||
v5.4.4
patch
| ||
v5.4.3
patch
| ||
v5.4.2
patch
| ||
v5.4.1
patch
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v5.4.0
minor
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v5.3.0
minor
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v5.2.1
patch
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v5.2.0
minor
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v5.1.1
patch
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev |
v5.1.1
patch
Changelog
Compare changes
|
|
v5.1.0
minor
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v5.0.6
patch
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v5.0.5
patch
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v5.0.4
patch
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v5.0.3
patch
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v5.0.2
patch
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v5.0.1
patch
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v5.0.0
major
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v4.17.1
patch
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v4.17.0
minor
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v4.16.0
minor
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v4.14
minor
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v4.13
minor
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v4.12
minor
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v4.11
minor
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v4.10
minor
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v4.9.4
patch
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v4.9.3
patch
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v4.9.2
patch
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v4.9.1
patch
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v4.9
minor
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v4.8.2
patch
1 CVE
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev | ||
v4.8.1
patch
2 CVEs
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-43960
GHSA-mqh4-2mm8-g7w9
Aug 25, 2025
Adminer PHP Object Injection issue leads to Denial of Service
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. Remote, unauthenticated attackers can trigger this by sending a malicious serialized object, which forces excessive memory usage, rendering Adminer’s interface unresponsive and causing a server-level DoS. While the server may recover after several minutes, multiple simultaneous requests can cause a complete crash requiring manual intervention. Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 14 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
References Updated Aug 25, 2025 · Source: OSV.dev | ||
v4.8.0
minor
3 CVEs
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-43960
GHSA-mqh4-2mm8-g7w9
Aug 25, 2025
Adminer PHP Object Injection issue leads to Denial of Service
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. Remote, unauthenticated attackers can trigger this by sending a malicious serialized object, which forces excessive memory usage, rendering Adminer’s interface unresponsive and causing a server-level DoS. While the server may recover after several minutes, multiple simultaneous requests can cause a complete crash requiring manual intervention. Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 14 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
References Updated Aug 25, 2025 · Source: OSV.dev
CVE-2021-29625
GHSA-2v82-5746-vwqc
Mar 18, 2022
XSS in doc_link
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
ImpactUsers of MySQL, MariaDB, PgSQL and SQLite are affected. XSS is in most cases prevented by strict CSP in all modern browsers. The only exception is when Adminer is using a PatchesPatched by 4043092, included in version 4.8.1. WorkaroundsDo both:
Referenceshttps://sourceforge.net/p/adminer/bugs-and-features/797/ For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.7.8
v4.7.9
v4.8.0
Fixed in
4.8.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v4.7.9
patch
3 CVEs
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-43960
GHSA-mqh4-2mm8-g7w9
Aug 25, 2025
Adminer PHP Object Injection issue leads to Denial of Service
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. Remote, unauthenticated attackers can trigger this by sending a malicious serialized object, which forces excessive memory usage, rendering Adminer’s interface unresponsive and causing a server-level DoS. While the server may recover after several minutes, multiple simultaneous requests can cause a complete crash requiring manual intervention. Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 14 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
References Updated Aug 25, 2025 · Source: OSV.dev
CVE-2021-29625
GHSA-2v82-5746-vwqc
Mar 18, 2022
XSS in doc_link
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
ImpactUsers of MySQL, MariaDB, PgSQL and SQLite are affected. XSS is in most cases prevented by strict CSP in all modern browsers. The only exception is when Adminer is using a PatchesPatched by 4043092, included in version 4.8.1. WorkaroundsDo both:
Referenceshttps://sourceforge.net/p/adminer/bugs-and-features/797/ For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.7.8
v4.7.9
v4.8.0
Fixed in
4.8.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v4.7.8
patch
5 CVEs
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-43960
GHSA-mqh4-2mm8-g7w9
Aug 25, 2025
Adminer PHP Object Injection issue leads to Denial of Service
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. Remote, unauthenticated attackers can trigger this by sending a malicious serialized object, which forces excessive memory usage, rendering Adminer’s interface unresponsive and causing a server-level DoS. While the server may recover after several minutes, multiple simultaneous requests can cause a complete crash requiring manual intervention. Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 14 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
References Updated Aug 25, 2025 · Source: OSV.dev
CVE-2021-29625
GHSA-2v82-5746-vwqc
Mar 18, 2022
XSS in doc_link
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
ImpactUsers of MySQL, MariaDB, PgSQL and SQLite are affected. XSS is in most cases prevented by strict CSP in all modern browsers. The only exception is when Adminer is using a PatchesPatched by 4043092, included in version 4.8.1. WorkaroundsDo both:
Referenceshttps://sourceforge.net/p/adminer/bugs-and-features/797/ For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.7.8
v4.7.9
v4.8.0
Fixed in
4.8.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-21311
GHSA-x5r2-hj5c-8jx6
Feb 11, 2021
SSRF in adminer
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers of Adminer versions bundling all drivers (e.g. PatchesPatched by ccd2374b, included in version 4.7.9. Workarounds
Referenceshttps://github.com/vrana/adminer/files/5957311/Adminer.SSRF.pdf For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 11 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
Fixed in
4.7.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-35572
GHSA-9pgx-gcph-mpqr
Feb 11, 2021
vrana/adminer via XSS in the history parameter in SQL command
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers of Adminer versions supporting SQL command (most versions, e.g. MySQL) using browsers not encoding URL parameters before sending to server (likely Edge, not Chrome, not Firefox) are affected. PatchesPatched by 5c395afc, included in version 4.7.9. WorkaroundsUse browser which encodes URL parameters (e.g. Chrome or Firefox). Referenceshttps://sourceforge.net/p/adminer/bugs-and-features/775/ For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 11 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
Fixed in
4.7.9
References
Updated Feb 17, 2024 · Source: OSV.dev | ||
v4.7.7
patch
5 CVEs
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-43960
GHSA-mqh4-2mm8-g7w9
Aug 25, 2025
Adminer PHP Object Injection issue leads to Denial of Service
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. Remote, unauthenticated attackers can trigger this by sending a malicious serialized object, which forces excessive memory usage, rendering Adminer’s interface unresponsive and causing a server-level DoS. While the server may recover after several minutes, multiple simultaneous requests can cause a complete crash requiring manual intervention. Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 14 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
References Updated Aug 25, 2025 · Source: OSV.dev
CVE-2018-7667
GHSA-43f8-p5w3-5m25
Feb 11, 2021
vrana/adminer vulnerable to SSRF by connecting to privileged ports
Medium
ImpactAll users are affected. Patches
WorkaroundsProtect access to Adminer also by other means, e.g. by HTTP password, IP address limiting or by OTP plugin. References
For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 10 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
Fixed in
4.7.8
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2021-21311
GHSA-x5r2-hj5c-8jx6
Feb 11, 2021
SSRF in adminer
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers of Adminer versions bundling all drivers (e.g. PatchesPatched by ccd2374b, included in version 4.7.9. Workarounds
Referenceshttps://github.com/vrana/adminer/files/5957311/Adminer.SSRF.pdf For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 11 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
Fixed in
4.7.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-35572
GHSA-9pgx-gcph-mpqr
Feb 11, 2021
vrana/adminer via XSS in the history parameter in SQL command
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers of Adminer versions supporting SQL command (most versions, e.g. MySQL) using browsers not encoding URL parameters before sending to server (likely Edge, not Chrome, not Firefox) are affected. PatchesPatched by 5c395afc, included in version 4.7.9. WorkaroundsUse browser which encodes URL parameters (e.g. Chrome or Firefox). Referenceshttps://sourceforge.net/p/adminer/bugs-and-features/775/ For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 11 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
Fixed in
4.7.9
References
Updated Feb 17, 2024 · Source: OSV.dev | ||
v4.7.6
patch
5 CVEs
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-43960
GHSA-mqh4-2mm8-g7w9
Aug 25, 2025
Adminer PHP Object Injection issue leads to Denial of Service
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. Remote, unauthenticated attackers can trigger this by sending a malicious serialized object, which forces excessive memory usage, rendering Adminer’s interface unresponsive and causing a server-level DoS. While the server may recover after several minutes, multiple simultaneous requests can cause a complete crash requiring manual intervention. Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 14 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
References Updated Aug 25, 2025 · Source: OSV.dev
CVE-2018-7667
GHSA-43f8-p5w3-5m25
Feb 11, 2021
vrana/adminer vulnerable to SSRF by connecting to privileged ports
Medium
ImpactAll users are affected. Patches
WorkaroundsProtect access to Adminer also by other means, e.g. by HTTP password, IP address limiting or by OTP plugin. References
For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 10 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
Fixed in
4.7.8
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2021-21311
GHSA-x5r2-hj5c-8jx6
Feb 11, 2021
SSRF in adminer
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers of Adminer versions bundling all drivers (e.g. PatchesPatched by ccd2374b, included in version 4.7.9. Workarounds
Referenceshttps://github.com/vrana/adminer/files/5957311/Adminer.SSRF.pdf For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 11 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
Fixed in
4.7.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-35572
GHSA-9pgx-gcph-mpqr
Feb 11, 2021
vrana/adminer via XSS in the history parameter in SQL command
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers of Adminer versions supporting SQL command (most versions, e.g. MySQL) using browsers not encoding URL parameters before sending to server (likely Edge, not Chrome, not Firefox) are affected. PatchesPatched by 5c395afc, included in version 4.7.9. WorkaroundsUse browser which encodes URL parameters (e.g. Chrome or Firefox). Referenceshttps://sourceforge.net/p/adminer/bugs-and-features/775/ For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 11 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
Fixed in
4.7.9
References
Updated Feb 17, 2024 · Source: OSV.dev | ||
v4.7.5
patch
5 CVEs
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-43960
GHSA-mqh4-2mm8-g7w9
Aug 25, 2025
Adminer PHP Object Injection issue leads to Denial of Service
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. Remote, unauthenticated attackers can trigger this by sending a malicious serialized object, which forces excessive memory usage, rendering Adminer’s interface unresponsive and causing a server-level DoS. While the server may recover after several minutes, multiple simultaneous requests can cause a complete crash requiring manual intervention. Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 14 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
References Updated Aug 25, 2025 · Source: OSV.dev
CVE-2018-7667
GHSA-43f8-p5w3-5m25
Feb 11, 2021
vrana/adminer vulnerable to SSRF by connecting to privileged ports
Medium
ImpactAll users are affected. Patches
WorkaroundsProtect access to Adminer also by other means, e.g. by HTTP password, IP address limiting or by OTP plugin. References
For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 10 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
Fixed in
4.7.8
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2021-21311
GHSA-x5r2-hj5c-8jx6
Feb 11, 2021
SSRF in adminer
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers of Adminer versions bundling all drivers (e.g. PatchesPatched by ccd2374b, included in version 4.7.9. Workarounds
Referenceshttps://github.com/vrana/adminer/files/5957311/Adminer.SSRF.pdf For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 11 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
Fixed in
4.7.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-35572
GHSA-9pgx-gcph-mpqr
Feb 11, 2021
vrana/adminer via XSS in the history parameter in SQL command
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers of Adminer versions supporting SQL command (most versions, e.g. MySQL) using browsers not encoding URL parameters before sending to server (likely Edge, not Chrome, not Firefox) are affected. PatchesPatched by 5c395afc, included in version 4.7.9. WorkaroundsUse browser which encodes URL parameters (e.g. Chrome or Firefox). Referenceshttps://sourceforge.net/p/adminer/bugs-and-features/775/ For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 11 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
Fixed in
4.7.9
References
Updated Feb 17, 2024 · Source: OSV.dev | ||
v4.7.4
patch
5 CVEs
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-43960
GHSA-mqh4-2mm8-g7w9
Aug 25, 2025
Adminer PHP Object Injection issue leads to Denial of Service
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. Remote, unauthenticated attackers can trigger this by sending a malicious serialized object, which forces excessive memory usage, rendering Adminer’s interface unresponsive and causing a server-level DoS. While the server may recover after several minutes, multiple simultaneous requests can cause a complete crash requiring manual intervention. Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 14 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
References Updated Aug 25, 2025 · Source: OSV.dev
CVE-2018-7667
GHSA-43f8-p5w3-5m25
Feb 11, 2021
vrana/adminer vulnerable to SSRF by connecting to privileged ports
Medium
ImpactAll users are affected. Patches
WorkaroundsProtect access to Adminer also by other means, e.g. by HTTP password, IP address limiting or by OTP plugin. References
For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 10 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
Fixed in
4.7.8
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2021-21311
GHSA-x5r2-hj5c-8jx6
Feb 11, 2021
SSRF in adminer
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers of Adminer versions bundling all drivers (e.g. PatchesPatched by ccd2374b, included in version 4.7.9. Workarounds
Referenceshttps://github.com/vrana/adminer/files/5957311/Adminer.SSRF.pdf For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 11 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
Fixed in
4.7.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-35572
GHSA-9pgx-gcph-mpqr
Feb 11, 2021
vrana/adminer via XSS in the history parameter in SQL command
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers of Adminer versions supporting SQL command (most versions, e.g. MySQL) using browsers not encoding URL parameters before sending to server (likely Edge, not Chrome, not Firefox) are affected. PatchesPatched by 5c395afc, included in version 4.7.9. WorkaroundsUse browser which encodes URL parameters (e.g. Chrome or Firefox). Referenceshttps://sourceforge.net/p/adminer/bugs-and-features/775/ For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 11 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
Fixed in
4.7.9
References
Updated Feb 17, 2024 · Source: OSV.dev | ||
v4.7.3
patch
5 CVEs
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-43960
GHSA-mqh4-2mm8-g7w9
Aug 25, 2025
Adminer PHP Object Injection issue leads to Denial of Service
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. Remote, unauthenticated attackers can trigger this by sending a malicious serialized object, which forces excessive memory usage, rendering Adminer’s interface unresponsive and causing a server-level DoS. While the server may recover after several minutes, multiple simultaneous requests can cause a complete crash requiring manual intervention. Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 14 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
References Updated Aug 25, 2025 · Source: OSV.dev
CVE-2018-7667
GHSA-43f8-p5w3-5m25
Feb 11, 2021
vrana/adminer vulnerable to SSRF by connecting to privileged ports
Medium
ImpactAll users are affected. Patches
WorkaroundsProtect access to Adminer also by other means, e.g. by HTTP password, IP address limiting or by OTP plugin. References
For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 10 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
Fixed in
4.7.8
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2021-21311
GHSA-x5r2-hj5c-8jx6
Feb 11, 2021
SSRF in adminer
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers of Adminer versions bundling all drivers (e.g. PatchesPatched by ccd2374b, included in version 4.7.9. Workarounds
Referenceshttps://github.com/vrana/adminer/files/5957311/Adminer.SSRF.pdf For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 11 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
Fixed in
4.7.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-35572
GHSA-9pgx-gcph-mpqr
Feb 11, 2021
vrana/adminer via XSS in the history parameter in SQL command
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers of Adminer versions supporting SQL command (most versions, e.g. MySQL) using browsers not encoding URL parameters before sending to server (likely Edge, not Chrome, not Firefox) are affected. PatchesPatched by 5c395afc, included in version 4.7.9. WorkaroundsUse browser which encodes URL parameters (e.g. Chrome or Firefox). Referenceshttps://sourceforge.net/p/adminer/bugs-and-features/775/ For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 11 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
Fixed in
4.7.9
References
Updated Feb 17, 2024 · Source: OSV.dev | ||
v4.7.2
patch
5 CVEs
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-43960
GHSA-mqh4-2mm8-g7w9
Aug 25, 2025
Adminer PHP Object Injection issue leads to Denial of Service
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. Remote, unauthenticated attackers can trigger this by sending a malicious serialized object, which forces excessive memory usage, rendering Adminer’s interface unresponsive and causing a server-level DoS. While the server may recover after several minutes, multiple simultaneous requests can cause a complete crash requiring manual intervention. Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 14 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
References Updated Aug 25, 2025 · Source: OSV.dev
CVE-2018-7667
GHSA-43f8-p5w3-5m25
Feb 11, 2021
vrana/adminer vulnerable to SSRF by connecting to privileged ports
Medium
ImpactAll users are affected. Patches
WorkaroundsProtect access to Adminer also by other means, e.g. by HTTP password, IP address limiting or by OTP plugin. References
For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 10 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
Fixed in
4.7.8
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2021-21311
GHSA-x5r2-hj5c-8jx6
Feb 11, 2021
SSRF in adminer
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers of Adminer versions bundling all drivers (e.g. PatchesPatched by ccd2374b, included in version 4.7.9. Workarounds
Referenceshttps://github.com/vrana/adminer/files/5957311/Adminer.SSRF.pdf For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 11 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
Fixed in
4.7.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-35572
GHSA-9pgx-gcph-mpqr
Feb 11, 2021
vrana/adminer via XSS in the history parameter in SQL command
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers of Adminer versions supporting SQL command (most versions, e.g. MySQL) using browsers not encoding URL parameters before sending to server (likely Edge, not Chrome, not Firefox) are affected. PatchesPatched by 5c395afc, included in version 4.7.9. WorkaroundsUse browser which encodes URL parameters (e.g. Chrome or Firefox). Referenceshttps://sourceforge.net/p/adminer/bugs-and-features/775/ For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 11 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
Fixed in
4.7.9
References
Updated Feb 17, 2024 · Source: OSV.dev | ||
v4.7.1
patch
5 CVEs
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-43960
GHSA-mqh4-2mm8-g7w9
Aug 25, 2025
Adminer PHP Object Injection issue leads to Denial of Service
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. Remote, unauthenticated attackers can trigger this by sending a malicious serialized object, which forces excessive memory usage, rendering Adminer’s interface unresponsive and causing a server-level DoS. While the server may recover after several minutes, multiple simultaneous requests can cause a complete crash requiring manual intervention. Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 14 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
References Updated Aug 25, 2025 · Source: OSV.dev
CVE-2018-7667
GHSA-43f8-p5w3-5m25
Feb 11, 2021
vrana/adminer vulnerable to SSRF by connecting to privileged ports
Medium
ImpactAll users are affected. Patches
WorkaroundsProtect access to Adminer also by other means, e.g. by HTTP password, IP address limiting or by OTP plugin. References
For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 10 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
Fixed in
4.7.8
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2021-21311
GHSA-x5r2-hj5c-8jx6
Feb 11, 2021
SSRF in adminer
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers of Adminer versions bundling all drivers (e.g. PatchesPatched by ccd2374b, included in version 4.7.9. Workarounds
Referenceshttps://github.com/vrana/adminer/files/5957311/Adminer.SSRF.pdf For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 11 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
Fixed in
4.7.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-35572
GHSA-9pgx-gcph-mpqr
Feb 11, 2021
vrana/adminer via XSS in the history parameter in SQL command
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers of Adminer versions supporting SQL command (most versions, e.g. MySQL) using browsers not encoding URL parameters before sending to server (likely Edge, not Chrome, not Firefox) are affected. PatchesPatched by 5c395afc, included in version 4.7.9. WorkaroundsUse browser which encodes URL parameters (e.g. Chrome or Firefox). Referenceshttps://sourceforge.net/p/adminer/bugs-and-features/775/ For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 11 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
Fixed in
4.7.9
References
Updated Feb 17, 2024 · Source: OSV.dev | ||
v4.7.0
minor
5 CVEs
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-43960
GHSA-mqh4-2mm8-g7w9
Aug 25, 2025
Adminer PHP Object Injection issue leads to Denial of Service
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. Remote, unauthenticated attackers can trigger this by sending a malicious serialized object, which forces excessive memory usage, rendering Adminer’s interface unresponsive and causing a server-level DoS. While the server may recover after several minutes, multiple simultaneous requests can cause a complete crash requiring manual intervention. Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 14 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
References Updated Aug 25, 2025 · Source: OSV.dev
CVE-2018-7667
GHSA-43f8-p5w3-5m25
Feb 11, 2021
vrana/adminer vulnerable to SSRF by connecting to privileged ports
Medium
ImpactAll users are affected. Patches
WorkaroundsProtect access to Adminer also by other means, e.g. by HTTP password, IP address limiting or by OTP plugin. References
For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 10 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
Fixed in
4.7.8
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2021-21311
GHSA-x5r2-hj5c-8jx6
Feb 11, 2021
SSRF in adminer
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers of Adminer versions bundling all drivers (e.g. PatchesPatched by ccd2374b, included in version 4.7.9. Workarounds
Referenceshttps://github.com/vrana/adminer/files/5957311/Adminer.SSRF.pdf For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 11 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
Fixed in
4.7.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-35572
GHSA-9pgx-gcph-mpqr
Feb 11, 2021
vrana/adminer via XSS in the history parameter in SQL command
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers of Adminer versions supporting SQL command (most versions, e.g. MySQL) using browsers not encoding URL parameters before sending to server (likely Edge, not Chrome, not Firefox) are affected. PatchesPatched by 5c395afc, included in version 4.7.9. WorkaroundsUse browser which encodes URL parameters (e.g. Chrome or Firefox). Referenceshttps://sourceforge.net/p/adminer/bugs-and-features/775/ For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 11 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
Fixed in
4.7.9
References
Updated Feb 17, 2024 · Source: OSV.dev | ||
v4.6.3
patch
5 CVEs
CVE-2026-25892
GHSA-q4f2-39gr-45jh
Feb 10, 2026
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryAdminer v5.4.1 has a version check mechanism where FixUpgrade to Adminer 5.4.2. Mitigation (if you can't upgrade): Make file Details1. Intended design of The endpoint is designed to receive version data from
2. The vulnerability: The endpoint only checks
3. Type confusion crash: When POST contains
PHP 8.x throws:
PoCSteps to Reproduce: Step 1: Verify Adminer is running and accessible.
Expected output:
Step 2: Send the malicious POST request. The
Expected output: Empty response (no error). Step 3: Access Adminer again to trigger the crash.
Expected output:
Step 4: (Optional) View the PHP error in server logs.
Step 5: (Optional) Inspect the poisoned file.
Expected output:
Recovery:
After deletion, Adminer returns HTTP 200. ImpactType: Denial of Service Root cause: The Affected users: Any Adminer instance accessible over the network. Affected versions
v4.10
v4.11
v4.12
v4.13
v4.14
v4.16.0
v4.17.0
v4.17.1
v4.6.2
v4.6.3
v4.7.0
v4.7.1
+ 30 more Show less
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
v4.8.2
v4.9
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
Fixed in
5.4.2
References Updated Feb 10, 2026 · Source: OSV.dev
CVE-2025-43960
GHSA-mqh4-2mm8-g7w9
Aug 25, 2025
Adminer PHP Object Injection issue leads to Denial of Service
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. Remote, unauthenticated attackers can trigger this by sending a malicious serialized object, which forces excessive memory usage, rendering Adminer’s interface unresponsive and causing a server-level DoS. While the server may recover after several minutes, multiple simultaneous requests can cause a complete crash requiring manual intervention. Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 14 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
v4.7.9
v4.8.0
v4.8.1
References Updated Aug 25, 2025 · Source: OSV.dev
CVE-2018-7667
GHSA-43f8-p5w3-5m25
Feb 11, 2021
vrana/adminer vulnerable to SSRF by connecting to privileged ports
Medium
ImpactAll users are affected. Patches
WorkaroundsProtect access to Adminer also by other means, e.g. by HTTP password, IP address limiting or by OTP plugin. References
For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 10 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
Fixed in
4.7.8
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2021-21311
GHSA-x5r2-hj5c-8jx6
Feb 11, 2021
SSRF in adminer
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers of Adminer versions bundling all drivers (e.g. PatchesPatched by ccd2374b, included in version 4.7.9. Workarounds
Referenceshttps://github.com/vrana/adminer/files/5957311/Adminer.SSRF.pdf For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 11 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
Fixed in
4.7.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-35572
GHSA-9pgx-gcph-mpqr
Feb 11, 2021
vrana/adminer via XSS in the history parameter in SQL command
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers of Adminer versions supporting SQL command (most versions, e.g. MySQL) using browsers not encoding URL parameters before sending to server (likely Edge, not Chrome, not Firefox) are affected. PatchesPatched by 5c395afc, included in version 4.7.9. WorkaroundsUse browser which encodes URL parameters (e.g. Chrome or Firefox). Referenceshttps://sourceforge.net/p/adminer/bugs-and-features/775/ For more informationIf you have any questions or comments about this advisory:
Affected versions
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.1
v4.4.0
v4.5.0
v4.6.0
v4.6.1
+ 11 more Show less
v4.6.2
v4.6.3
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.7.8
Fixed in
4.7.9
References
Updated Feb 17, 2024 · Source: OSV.dev |