Pgadmin 4
Pgadmin · 42 CVEs
pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-…
Jul 31, 2026
pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE…
Jul 31, 2026
pgAdmin 4: Tool permission bypass via backend routes and Socket.IO handlers
Jul 31, 2026
pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner
Jul 31, 2026
pgAdmin 4: Missing authentication decorator on Constraints, preferences, Debugger and Schema Diff routes allows unauthe…
Jul 31, 2026
pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution
Jul 31, 2026
pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views (…
Jul 31, 2026
pgAdmin 4: Open redirect in multi-factor authentication flow via unvalidated 'next' parameter
Jun 18, 2026
pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-parser
Jun 18, 2026
pgAdmin 4: HTML injection in cloud verify_credentials / deploy endpoints via unsanitised SDK exception text
Jun 18, 2026
pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code ex…
Jun 18, 2026
pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code execution
Jun 18, 2026
pgAdmin 4: SQL injection in named restore point endpoint
Jun 18, 2026
pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog templates
Jun 18, 2026
pgAdmin 4: Account-lockout bypass via Flask-Security default /login view
May 11, 2026
pgAdmin 4: Symbolic-link path traversal in File Manager allows arbitrary file write
May 11, 2026
pgAdmin 4: Unsafe deserialization (CWE-502) in file-backed session manager leads to remote code execution
May 11, 2026
pgAdmin 4: Local file inclusion and server-side request forgery in LLM API configuration endpoints
May 11, 2026
pgAdmin 4: OS command injection in Import/Export query export via psql metacommand breakout
May 11, 2026
pgAdmin 4: SQL injection in Maintenance tool option values leading to remote code execution
May 11, 2026
pgAdmin 4: Stored XSS via crafted PostgreSQL object names in Browser Tree and Explain Visualizer
May 11, 2026
pgAdmin 4: Cross-user data access and shared-server privilege escalation in server mode
May 11, 2026
Restore restriction bypass via key disclosure vulnerability (pgAdmin 4)
Feb 5, 2026
Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)
Dec 11, 2025
pgAdmin 4: LDAP authentication flow vulnerable to TLS certificate verification bypass.
Nov 13, 2025
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-17566 | pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780) | CRITICAL | 0.67% | Jul 31, 2026 |
| CVE-2026-17351 | pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045) | CRITICAL | 0.48% | Jul 31, 2026 |
| CVE-2026-17350 | pgAdmin 4: Tool permission bypass via backend routes and Socket.IO handlers | MEDIUM | 0.38% | Jul 31, 2026 |
| CVE-2026-17349 | pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner | CRITICAL | 0.40% | Jul 31, 2026 |
| CVE-2026-17348 | pgAdmin 4: Missing authentication decorator on Constraints, preferences, Debugger and Schema Diff routes allows unauthenticated access in SERVER mode (incomple… | MEDIUM | 0.42% | Jul 31, 2026 |
| CVE-2026-17347 | pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution | HIGH | 0.72% | Jul 31, 2026 |
| CVE-2026-17346 | pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views (incomplete fix for CVE-2026-12044) | HIGH | 0.61% | Jul 31, 2026 |
| CVE-2026-12049 | pgAdmin 4: Open redirect in multi-factor authentication flow via unvalidated 'next' parameter | MEDIUM | 0.38% | Jun 18, 2026 |
| CVE-2026-12048 | pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-parser | CRITICAL | 0.27% | Jun 18, 2026 |
| CVE-2026-12047 | pgAdmin 4: HTML injection in cloud verify_credentials / deploy endpoints via unsanitised SDK exception text | MEDIUM | 0.22% | Jun 18, 2026 |
| CVE-2026-12046 | pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code execution | CRITICAL | 1.04% | Jun 18, 2026 |
| CVE-2026-12045 | pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code execution | CRITICAL | 0.66% | Jun 18, 2026 |
| CVE-2026-12050 | pgAdmin 4: SQL injection in named restore point endpoint | MEDIUM | 0.43% | Jun 18, 2026 |
| CVE-2026-12044 | pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog templates | HIGH | 0.71% | Jun 18, 2026 |
| CVE-2026-7820 | pgAdmin 4: Account-lockout bypass via Flask-Security default /login view | MEDIUM | 0.33% | May 11, 2026 |
| CVE-2026-7819 | pgAdmin 4: Symbolic-link path traversal in File Manager allows arbitrary file write | HIGH | 0.48% | May 11, 2026 |
| CVE-2026-7818 | pgAdmin 4: Unsafe deserialization (CWE-502) in file-backed session manager leads to remote code execution | HIGH | 0.35% | May 11, 2026 |
| CVE-2026-7817 | pgAdmin 4: Local file inclusion and server-side request forgery in LLM API configuration endpoints | HIGH | 0.35% | May 11, 2026 |
| CVE-2026-7816 | pgAdmin 4: OS command injection in Import/Export query export via psql metacommand breakout | HIGH | 2.18% | May 11, 2026 |
| CVE-2026-7815 | pgAdmin 4: SQL injection in Maintenance tool option values leading to remote code execution | HIGH | 0.64% | May 11, 2026 |
| CVE-2026-7814 | pgAdmin 4: Stored XSS via crafted PostgreSQL object names in Browser Tree and Explain Visualizer | MEDIUM | 0.25% | May 11, 2026 |
| CVE-2026-7813 | pgAdmin 4: Cross-user data access and shared-server privilege escalation in server mode | CRITICAL | 0.65% | May 11, 2026 |
| CVE-2026-1707 | Restore restriction bypass via key disclosure vulnerability (pgAdmin 4) | HIGH | 0.45% | Feb 5, 2026 |
| CVE-2025-13780 | Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4) | CRITICAL | 0.94% | Dec 11, 2025 |
| CVE-2025-12765 | pgAdmin 4: LDAP authentication flow vulnerable to TLS certificate verification bypass. | HIGH | 0.22% | Nov 13, 2025 |
Showing 1 to 25 of 42 CVEs