Vulnerabilities > Phppgadmin Project

DATE CVE VULNERABILITY TITLE RISK
2023-09-20 CVE-2023-40619 Deserialization of Untrusted Data vulnerability in PHPpgadmin Project PHPpgadmin
phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is directly passed to the PHP 'unserialize()' function in multiple places.
network
low complexity
phppgadmin-project CWE-502
critical
9.8
2020-02-04 CVE-2019-10784 Cross-Site Request Forgery (CSRF) vulnerability in PHPpgadmin Project PHPpgadmin
phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application.
network
phppgadmin-project CWE-352
critical
9.3