Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/vrana/adminer

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Adminer 5.5.1 through 6.0.1 improperly parses the login 'server' string in the host_port() function in adminer/include/functions.inc.php. The port capture group requires pure digits anchored to the end of the string, so any server value with a non-digit tail fails the regex and falls back to returning the whole string as the host with an empty port. Because the privileged-port restriction in adminer/include/auth.inc.php inspects only the parsed port, the check is skipped, and the mysqli/mysqlnd client subsequently re-parses host:port from the host string and opens a TCP connection. A remote, unauthenticated attacker who can reach the Adminer login page can submit a crafted value such as 127.0.0.1:80/x to make the server initiate TCP connections to arbitrary internal hosts and privileged ports before credentials are validated, enabling server-side request forgery and blind internal port scanning (connection refused vs. handshake vs. timeout acts as a liveness oracle). This is a regression that re-opens the bypass fixed in 5.5.0 (GHSA-58cq-mgw2-38m5). Fixed in 6.0.2.

Join the discussion

Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.0.0) is loaded, is vulnerable to pre-authentication server-side request forgery. An unauthenticated attacker can submit auth[driver]=clickhouse with auth[server] set to an arbitrary URL (for example http://127.0.0.1:18089), causing the Adminer server to issue an HTTP POST containing 'SELECT version()' to that host. In rootQuery(), if the target returns a status outside 200-299 (other than 401/403), the raw HTTP response body is assigned to the connection error and rendered on the login page, so the attacker receives the full response body of the internal service. This enables internal network/port reconnaissance and disclosure of sensitive information contained in internal error pages (stack traces, internal hostnames, file paths, configuration identifiers). Fixed in Adminer 6.0.2.

Join the discussion

Adminer 4.16.0 through 6.0.1 contain a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the optional Elasticsearch driver (plugins/drivers/elastic.php), fixed in 6.0.2. Because adminer/include/auth.inc.php invokes Driver::connect() before the login result is validated, an unauthenticated attacker who submits crafted auth[server], auth[username], and auth[password] parameters can cause the Adminer server to issue an HTTP GET request (via get_url()/file_get_contents()) to an arbitrary reachable host and port. The driver validates only general server syntax and does not block loopback, private, link-local, or other reserved addresses; if no port is given it appends the default 9200, and Adminer's generic port check rejects ports below 1024. Selected JSON error fields from non-2xx Elasticsearch-style responses, as well as connection failures, are rendered on the login page, providing a port-scanning oracle and enabling internal network reconnaissance and service fingerprinting. Exploitation requires that the optional Elasticsearch driver be explicitly deployed (e.g., via the adminer/elastic.php template or an adminer_object() configuration; it is not loaded in a default build) and that PHP allow_url_fopen be enabled.

Join the discussion

Adminer before 6.0.2 contains a cross-site scripting vulnerability where the CONNECTION_ID() database result is interpolated into JavaScript without proper escaping, allowing a malicious database server to execute arbitrary JavaScript in the authenticated Adminer origin. In co-located deployments where the database has FILE privileges and can write to the webroot, attackers can use the XSS to submit authenticated SQL requests that write PHP files via INTO DUMPFILE, achieving remote code execution as the web server account.

Join the discussion

Adminer versions before 5.4.3 contain a vulnerability where the server field is not properly sanitized before constructing a PDO DSN string. This allows unauthenticated attackers to inject ODBC parameters via semicolons, including TraceFile and TraceOn, which can be used to write PHP code to the web root and achieve remote code execution.

Join the discussion

CVE-2026-56704 is a cross-site scripting (XSS) vulnerability in Adminer before version 5.4.3. The issue arises because unsanitized database server version strings are inserted into script tags with valid Content Security Policy (CSP) nonces without proper validation. This allows an attacker controlling a rogue MySQL server to craft malicious version strings that break out of the JavaScript context and execute arbitrary code, bypassing CSP protections.

Join the discussion

Adminer versions prior to 5.4.3 contain a remote code execution vulnerability related to improper handling of SQLite VACUUM INTO commands. Authenticated attackers can exploit this flaw to write and execute arbitrary PHP code on the server by bypassing ATTACH restrictions. This vulnerability has a high severity rating and a CVSS score of 8.6.

Join the discussion

Adminer versions prior to 5.4.3 contain a path traversal vulnerability in SQLite mode that allows authenticated users to delete arbitrary files writable by the PHP process. This occurs because the database-list drop action does not properly validate file extensions before deletion, enabling attackers to submit crafted relative file paths via the db[] parameter.

Join the discussion

Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in the ns parameter of plugins/sql-log.php. An authenticated user can supply path traversal sequences in the ns parameter to write arbitrary .sql files with attacker-controlled content to any writable directory on the host.

Join the discussion

Adminer versions prior to 5.5.0 contain a server-side request forgery (SSRF) vulnerability in the login form's server field validator. The validator incorrectly inspects only leading integers for privileged ports and fails to reject non-numeric port values. This flaw allows attackers to inject PDO DSN keys such as host= and port= into the server parameter, bypassing privileged-port restrictions and enabling TCP connections to arbitrary internal hosts and ports before authentication.

Join the discussion

Showing 1 to 10 of 13 results

Filters:Package: pkg:github/vrana/adminer
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses