CVE-2018-19969: phpMyAdmin

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is possible to perform harmful SQL operations such as renaming databases, creating new tables/routines, deleting designer pages, adding/deleting users, updating user passwords, killing SQL processes, etc.

Affected products

  • phpMyAdmin phpMyAdmin: from 4.7.0, up to and including 4.7.6; from 4.8.0, before 4.8.4 (fixed in 4.8.4)

Published 2018-12-11. Last modified 2026-06-17.