This page lists publicly disclosed CVE vulnerabilities affecting craigtaub phpmsadmin (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2025-63948 | A SQL Injection vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary SQL commands via the dbname parameter, potentially leading to information disclosure or database manipulation. | [email protected] | 5.4 | 0.02% | 2025-12-18 | 2025-12-31 |
| CVE-2025-63947 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary web script or HTML via the dbname parameter after a user is authenticated. | [email protected] | 5.4 | 0.02% | 2025-12-18 | 2026-01-06 |