Adminer records
7 published records for vendor adminer.
Researcher profile
- Entered KEV
- 1 · 14.3%
- Weaponized
- 1 · 14.3%
- Pre-auth RCE
- 0
- With a fix record
- 85.7%
- Median publish → KEV
- 1691 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-20 Improper Input Validation1
- CWE-502 Deserialization of Untrusted Data1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
88Now | CVE-2021-21311Weaponized | Adminer is an open-source database management in a single PHP file.adminer · adminer · CWE-918 | High7.2 | KEV | 98.5% | Feb 11, 2021 |
40Plan | CVE-2018-7667No exploit | Adminer through 4.3.1 has SSRF via the server parameter.adminer · adminer · CWE-918 | Critical9.8 | — | 4.4% | Mar 5, 2018 |
34Monitor | CVE-2021-43008Proof of concept | Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on thadminer · adminer | High7.5 | — | 13.6% | Apr 4, 2022 |
34Monitor | CVE-2025-43960Proof of concept | Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., usingadminer · adminer · CWE-502 | High8.6 | — | 0.7% | Aug 25, 2025 |
31Monitor | CVE-2026-25892Proof of concept | Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpointadminer · adminer · CWE-20 | High7.5 | — | 1.9% | Feb 9, 2026 |
27Monitor | CVE-2021-29625Proof of concept | Adminer is open-source database management software.adminer · adminer · CWE-79 | Medium6.1 | — | 9.6% | May 19, 2021 |
25Monitor | CVE-2020-35572No exploit | Adminer through 4.7.8 allows XSS via the history parameter to the default URI.adminer · adminer · CWE-79 | Medium6.1 | — | 2.0% | Feb 9, 2021 |
- CVE-2021-2131188Now
Adminer is an open-source database management in a single PHP file.
HighCVSS 7.2KEVWeaponizedEPSS 98%adminer · adminerFeb 11, 2021
- CVE-2018-766740Plan
Adminer through 4.3.1 has SSRF via the server parameter.
CriticalCVSS 9.8No exploitEPSS 4%adminer · adminerMar 5, 2018
- CVE-2021-4300834Monitor
Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on th
HighCVSS 7.5Proof of conceptEPSS 14%adminer · adminerApr 4, 2022
- CVE-2025-4396034Monitor
Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using
HighCVSS 8.6Proof of conceptEPSS 1%adminer · adminerAug 25, 2025
- CVE-2026-2589231Monitor
Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
HighCVSS 7.5Proof of conceptEPSS 2%adminer · adminerFeb 9, 2026
- CVE-2021-2962527Monitor
Adminer is open-source database management software.
MediumCVSS 6.1Proof of conceptEPSS 10%adminer · adminerMay 19, 2021
- CVE-2020-3557225Monitor
Adminer through 4.7.8 allows XSS via the history parameter to the default URI.
MediumCVSS 6.1No exploitEPSS 2%adminer · adminerFeb 9, 2021