peter bassill · operator
$ cve CVE-2021-21311 JSON

CVE-2021-21311 KEV

7.2
HIGH · CVSS 3.1 · EPSS 98.5% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2025-10-20.

Description

Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This is fixed in version 4.7.9.

Scoring

CVSS7.2 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
EPSS98.46% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-918
On CISA KEVyes — remediate by 2025-10-20
Public exploitnone known
Published2021-02-11
Last modified2026-06-17

CISA KEV

NameAdminer Server-Side Request Forgery Vulnerability
Added2025-09-29
Due2025-10-20
Vendor / productAdminer / Adminer
Ransomware usenone reported

Affected (2)

VendorProduct
admineradminer
debiandebian linux

References

→ the Explorer  ·  watch your stack  ·  NVD