CVE-2021-21311

SSRF in adminer

Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This is fixed in version 4.7.9.


We have discovered 161 live websites that are affected by CVE-2021-21311.

Run a Free Instant Scan




Affected Software

Product  Adminer
Category Database Managers
Vulnerable Domains161 live websites (34% of Adminer install base)
Vulnerable Versions
  • from 4 through 4.7.9
Vulnerable Versions Count12 versions ( 33% of all versions)


Common Weakness Enumeration

CWE-918 Server-Side Request Forgery (SSRF)



Details

  • Published - Feb 11, 2021
  • Updated - Oct 21, 2025

Website Distribution by Country

Number of websites using CVE-2021-21311
United States24 websites



Czech Republic74 websites
Germany28 websites
Netherlands7 websites
Lithuania6 websites
Australia4 websites
India3 websites
Russia3 websites
Switzerland2 websites
China2 websites

Website Distribution by TLD

Number of websites using CVE-2021-21311
.cz70 websites
.com24 websites
.eu7 websites
.nl6 websites
.ch5 websites
.de4 websites
.net4 websites
.ru3 websites
.org3 websites
.it2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2021-21311

Top websites that are affected by CVE-2021-21311. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****************.**.********.com United States*,***,***
*********.********.com United States*,***,***
***********************.**.********.com United States*,***,***
****.*********.cz Czech Republic*,***,***
*********.*******.pro Germany*,***,***
***.*******.pro Germany*,***,***
****.********.cz Czech Republic*,***,***
*****.********.ch Germany*,***,***
****.*******.pro Germany*,***,***
*********.*******.pro Germany*,***,***
See full domain list

FAQ

CVE-2021-21311 is Server-Side Request Forgery (SSRF) in Adminer
A total of 161 websites have been identified as vulnerable to CVE-2021-21311, based on global website indexing conducted by WebTechSurvey.
The Adminer is affected by the CVE-2021-21311 vulnerability.
Adminer versions up to 4.7.9 are vulnerable to CVE-2021-21311.
CVE-2021-21311 is resolved in version 4.7.9 of Adminer.