CVE-2016-5731: Opensuse Leap

Medium severity, CVSS 6.1. EPSS: 1.8% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in examples/openid.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to inject arbitrary web script or HTML via vectors involving an OpenID error message.

Affected products

  • Opensuse Leap: version 42.1 only
  • Opensuse Opensuse: version 13.1 only; version 13.2 only
  • phpMyAdmin phpMyAdmin: version 4.6.0 only; version 4.6.1 only; version 4.6.2 only; version 4.0.0 only; version 4.0.1 only; version 4.0.2 only; …

Published 2016-07-03. Last modified 2026-06-17.