CVE-2026-56704

Adminer before 5.4.3 Cross-Site Scripting via MySQL Version String

Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without proper validation. Attackers controlling a rogue MySQL server can return crafted version strings that break out of the JavaScript context and execute arbitrary code, bypassing Content Security Policy protections.


We have discovered 271 live websites that are affected by CVE-2026-56704.

Run a Free Instant Scan




Affected Software

Product  Adminer
Category Database Managers
Vulnerable Domains271 live websites (100% of Adminer install base)
Vulnerable Versions
  • from 0 through 5.4.3
Vulnerable Versions Count16 versions ( 89% of all versions)



Details

  • Published - Aug 25, 2026
  • Updated - Aug 26, 2026

Credits

  • AmirMSafari (reporter)

Website Distribution by Country

Number of websites using CVE-2026-56704
United States43 websites



Czech Republic87 websites
Germany55 websites
France26 websites
Slovakia9 websites
Sweden7 websites
Belgium6 websites
Australia4 websites
China4 websites
Spain4 websites

Website Distribution by TLD

Number of websites using CVE-2026-56704
.cz83 websites
.com61 websites
.de24 websites
.net19 websites
.eu14 websites
.fr8 websites
.se6 websites
.be5 websites
.ch5 websites
.ru4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-56704

Top websites that are affected by CVE-2026-56704. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.********.com Czech Republic**,***
*******.*****.cz Czech Republic***,***
******.*************.cz Czech Republic***,***
*******.***.cn China***,***
***.*******.net Poland*,***,***
***.*************.de Germany*,***,***
****.********.net United States*,***,***
********.cz Germany*,***,***
***.**************.de Germany*,***,***
*****************.*******************.de Germany*,***,***
See full domain list

FAQ

A total of 271 websites have been identified as vulnerable to CVE-2026-56704, based on global website indexing conducted by WebTechSurvey.
The Adminer is affected by the CVE-2026-56704 vulnerability.
Adminer versions up to 5.4.3 are vulnerable to CVE-2026-56704.
CVE-2026-56704 is resolved in version 5.4.3 of Adminer.