CVE-2020-22278: phpMyAdmin

High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.

phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.

Affected products

Published 2020-11-04. Last modified 2026-06-17.