CVE Browser
pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)
pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)
pgAdmin 4: Tool permission bypass via backend routes and Socket.IO handlers
pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner
pgAdmin 4: Missing authentication decorator on Constraints, preferences, Debugger and Schema Diff routes allows unauthenticated access in SERVER mode (incomple…
pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution
pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views (incomplete fix for CVE-2026-12044)
pgAdmin 4: Open redirect in multi-factor authentication flow via unvalidated 'next' parameter
pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-parser
pgAdmin 4: HTML injection in cloud verify_credentials / deploy endpoints via unsanitised SDK exception text
pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code execution
pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code execution
pgAdmin 4: SQL injection in named restore point endpoint
pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog templates
pgAdmin 4: Account-lockout bypass via Flask-Security default /login view
pgAdmin 4: Symbolic-link path traversal in File Manager allows arbitrary file write
pgAdmin 4: Unsafe deserialization (CWE-502) in file-backed session manager leads to remote code execution
pgAdmin 4: Local file inclusion and server-side request forgery in LLM API configuration endpoints
pgAdmin 4: OS command injection in Import/Export query export via psql metacommand breakout
pgAdmin 4: SQL injection in Maintenance tool option values leading to remote code execution
pgAdmin 4: Stored XSS via crafted PostgreSQL object names in Browser Tree and Explain Visualizer
pgAdmin 4: Cross-user data access and shared-server privilege escalation in server mode
Restore restriction bypass via key disclosure vulnerability (pgAdmin 4)
Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)
pgAdmin 4: LDAP authentication flow vulnerable to TLS certificate verification bypass.
Showing 1 to 25 CVEs · page 1 (more available)