Pgadmin 4

Pgadmin · 42 CVEs

CVE-2026-17566
CRITICAL

pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-…

Jul 31, 2026

CVE-2026-17351
CRITICAL

pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE…

Jul 31, 2026

CVE-2026-17350
MEDIUM

pgAdmin 4: Tool permission bypass via backend routes and Socket.IO handlers

Jul 31, 2026

CVE-2026-17349
CRITICAL

pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner

Jul 31, 2026

CVE-2026-17348
MEDIUM

pgAdmin 4: Missing authentication decorator on Constraints, preferences, Debugger and Schema Diff routes allows unauthe…

Jul 31, 2026

CVE-2026-17347
HIGH

pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution

Jul 31, 2026

CVE-2026-17346
HIGH

pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views (…

Jul 31, 2026

CVE-2026-12049
MEDIUM

pgAdmin 4: Open redirect in multi-factor authentication flow via unvalidated 'next' parameter

Jun 18, 2026

CVE-2026-12048
CRITICAL

pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-parser

Jun 18, 2026

CVE-2026-12047
MEDIUM

pgAdmin 4: HTML injection in cloud verify_credentials / deploy endpoints via unsanitised SDK exception text

Jun 18, 2026

CVE-2026-12046
CRITICAL

pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code ex…

Jun 18, 2026

CVE-2026-12045
CRITICAL

pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code execution

Jun 18, 2026

CVE-2026-12050
MEDIUM

pgAdmin 4: SQL injection in named restore point endpoint

Jun 18, 2026

CVE-2026-12044
HIGH

pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog templates

Jun 18, 2026

CVE-2026-7820
MEDIUM

pgAdmin 4: Account-lockout bypass via Flask-Security default /login view

May 11, 2026

CVE-2026-7819
HIGH

pgAdmin 4: Symbolic-link path traversal in File Manager allows arbitrary file write

May 11, 2026

CVE-2026-7818
HIGH

pgAdmin 4: Unsafe deserialization (CWE-502) in file-backed session manager leads to remote code execution

May 11, 2026

CVE-2026-7817
HIGH

pgAdmin 4: Local file inclusion and server-side request forgery in LLM API configuration endpoints

May 11, 2026

CVE-2026-7816
HIGH

pgAdmin 4: OS command injection in Import/Export query export via psql metacommand breakout

May 11, 2026

CVE-2026-7815
HIGH

pgAdmin 4: SQL injection in Maintenance tool option values leading to remote code execution

May 11, 2026

CVE-2026-7814
MEDIUM

pgAdmin 4: Stored XSS via crafted PostgreSQL object names in Browser Tree and Explain Visualizer

May 11, 2026

CVE-2026-7813
CRITICAL

pgAdmin 4: Cross-user data access and shared-server privilege escalation in server mode

May 11, 2026

CVE-2026-1707
HIGH

Restore restriction bypass via key disclosure vulnerability (pgAdmin 4)

Feb 5, 2026

CVE-2025-13780
CRITICAL

Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)

Dec 11, 2025

CVE-2025-12765
HIGH

pgAdmin 4: LDAP authentication flow vulnerable to TLS certificate verification bypass.

Nov 13, 2025

Showing 1 to 25 of 42 CVEs