VendorsApachefriendsxamppany version
Vulnerabilities

Apachefriends XAMPP any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2019-8923
XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued.
Published 2019-05-14 · Modified
9.81 PoCEPSS 0.039
CVE-2024-0338
Buffer Overflow Vulnerability in XAMPP
Published 2024-02-02 · Modified
9.8EPSS 0.005
CVE-2020-11107
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe configuration in xampp-contol.ini for all users (including admins) to enable arbitrary command execution.
Published 2020-04-02 · Modified
8.81 PoCEPSS 0.225
CVE-2022-29376
Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via overwriting binaries located in the directory.
Published 2022-05-23 · Modified
8.8EPSS 0.014
CVE-2022-47637
The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory. Common use cases execute files under C:\xampp with administrative privileges.
Published 2023-09-12 · Modified
6.7EPSS 0.003
CVE-2019-8924
XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued.
Published 2019-05-17 · Modified
6.11 PoCEPSS 0.057