VendorspgAdminpgadmin_4all versions
Vulnerabilities

pgAdmin Pgadmin 4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

46CVEs
CVE-2023-22298
Open redirect vulnerability in pgAdmin 4 versions prior to v6.14 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.
Published 2023-01-17 · Modified
6.1EPSS 0.009
CVE-2026-12049
pgAdmin 4: Open redirect in multi-factor authentication flow via unvalidated 'next' parameter
Published 2026-06-18 · Analyzed
6.1EPSS 0.004
CVE-2026-86861
pgAdmin 4: File Manager save_file writes through a symbolic link planted after the containment check
Published 2026-09-17 · Analyzed
6.0EPSS 0.003
CVE-2026-17350
pgAdmin 4: Tool permission bypass via backend routes and Socket.IO handlers
Published 2026-07-31 · Analyzed
5.4EPSS 0.004
CVE-2026-12047
pgAdmin 4: HTML injection in cloud verify_credentials / deploy endpoints via unsanitised SDK exception text
Published 2026-06-18 · Analyzed
5.4EPSS 0.002
CVE-2026-7814
pgAdmin 4: Stored XSS via crafted PostgreSQL object names in Browser Tree and Explain Visualizer
Published 2026-05-11 · Analyzed
4.8EPSS 0.002
← Prev2 / 2