Vulnerabilities > Phppgadmin Project

DATE CVE VULNERABILITY TITLE RISK
2023-09-20 CVE-2023-40619 Deserialization of Untrusted Data vulnerability in PHPpgadmin Project PHPpgadmin
phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is directly passed to the PHP 'unserialize()' function in multiple places.
network
low complexity
phppgadmin-project CWE-502
critical
9.8
2020-02-04 CVE-2019-10784 Cross-Site Request Forgery (CSRF) vulnerability in PHPpgadmin Project PHPpgadmin
phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application.
network
low complexity
phppgadmin-project CWE-352
critical
9.6