Adminer · Adminer · CVE-2026-34968
**Name of the Vulnerable Software and Affected Versions**
Adminer versions prior to 5.4.3
**Description**
In SQLite mode, the database-list drop action fails to validate file extensions before deletion. An authenticated attacker can submit arbitrary relative file paths via the `db[]` parameter to delete any files writable by the PHP process.
**Recommendations**
Update to version 5.4.3 or later.