VendorspgAdminpgadmin_4any version
Vulnerabilities

pgAdmin Pgadmin 4 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

45CVEs
CVE-2024-2044
Unsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4
Published 2024-03-07 · Analyzed
9.9EPSS 0.795
CVE-2025-2945
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
Published 2025-04-03 · Analyzed
9.9EPSS 0.563
CVE-2024-9014
OAuth2 client id and secret exposed through the web browser in pgAdmin 4
Published 2024-09-23 · Analyzed
9.9EPSS 0.097
CVE-2026-17566
pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)
Published 2026-07-31 · Analyzed
9.9EPSS 0.007
CVE-2026-7813
pgAdmin 4: Cross-user data access and shared-server privilege escalation in server mode
Published 2026-05-11 · Analyzed
9.9EPSS 0.007
CVE-2024-3116
Remote Code Execution Vulnerability through the validate binary path API in pgAdmin 4
Published 2024-04-04 · Modified
9.8EPSS 0.656
CVE-2025-12762
Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)
Published 2025-11-13 · Modified
9.8EPSS 0.127
CVE-2026-86863
pgAdmin 4: Authentication bypass via a client-controlled identity header in Webserver authentication mode
Published 2026-09-17 · Analyzed
9.8EPSS 0.006
CVE-2026-17349
pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner
Published 2026-07-31 · Analyzed
9.6EPSS 0.004
CVE-2026-12046
pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code execution
Published 2026-06-18 · Analyzed
9.5EPSS 0.010
CVE-2026-12045
pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code execution
Published 2026-06-18 · Analyzed
9.4EPSS 0.007
CVE-2026-17351
pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)
Published 2026-07-31 · Analyzed
9.4EPSS 0.005
CVE-2026-12048
pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-parser
Published 2026-06-18 · Analyzed
9.3EPSS 0.003
CVE-2025-13780
Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)
Published 2025-12-11 · Analyzed
9.1EPSS 0.009
CVE-2025-2946
Cross-Site Vulnerability(XSS) due to arbitrary HTML/JavaScript gets executed while query result rendering in Query Tool and View/Edit Data Tool of pgAdmin 4
Published 2025-04-03 · Analyzed
9.1EPSS 0.003
CVE-2022-4223
The pgAdmin server includes an HTTP API that is intended to be used to validate the path a user selects to external PostgreSQL utilities such as pg_dump and pg_restore. The utility is executed by the server to determine what PostgreSQL version it is from. Versions of pgAdmin prior to 6.17 failed to properly secure this API, which could allow an unauthenticated user to call it with a path of their choosing, such as a UNC path to a server they control on a Windows machine. This would cause an appropriately named executable in the target path to be executed by the pgAdmin server.
Published 2022-12-13 · Modified
8.8EPSS 0.801
CVE-2026-7816
pgAdmin 4: OS command injection in Import/Export query export via psql metacommand breakout
Published 2026-05-11 · Modified
8.8EPSS 0.022
CVE-2023-5002
Pgadmin4: remote code execution by an authenticated user
Published 2023-09-22 · Modified
8.8EPSS 0.018
CVE-2025-12763
Command injection vulnerability allowing arbitrary command execution on Windows
Published 2025-11-13 · Modified
8.8EPSS 0.009
CVE-2026-17347
pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution
Published 2026-07-31 · Analyzed
8.8EPSS 0.007
CVE-2026-12044
pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog templates
Published 2026-06-18 · Analyzed
8.8EPSS 0.007
CVE-2026-7815
pgAdmin 4: SQL injection in Maintenance tool option values leading to remote code execution
Published 2026-05-11 · Analyzed
8.8EPSS 0.006
CVE-2024-4215
The Multi Factor Authentication bypass vulnerability in pgAdmin 4
Published 2024-05-02 · Analyzed
8.8EPSS 0.006
CVE-2026-17346
pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views (incomplete fix for CVE-2026-12044)
Published 2026-07-31 · Analyzed
8.8EPSS 0.006
CVE-2026-86864
pgAdmin 4: Argument and connection-string injection via the database field in the Backup tool
Published 2026-09-17 · Analyzed
8.8EPSS 0.006
CVE-2026-12050
pgAdmin 4: SQL injection in named restore point endpoint
Published 2026-06-18 · Analyzed
8.8EPSS 0.004
CVE-2026-7819
pgAdmin 4: Symbolic-link path traversal in File Manager allows arbitrary file write
Published 2026-05-11 · Analyzed
8.1EPSS 0.005
CVE-2025-9636
Cross-Origin Opener Policy Vulnerability in pgAdmin 4
Published 2025-09-04 · Analyzed
7.9EPSS 0.002
CVE-2026-7818
pgAdmin 4: Unsafe deserialization (CWE-502) in file-backed session manager leads to remote code execution
Published 2026-05-11 · Analyzed
7.8EPSS 0.004
CVE-2025-12764
pgAdmin 4: LDAP injection vulnerability in LDAP authentication flow.
Published 2025-11-13 · Analyzed
7.5EPSS 0.004
CVE-2025-12765
pgAdmin 4: LDAP authentication flow vulnerable to TLS certificate verification bypass.
Published 2025-11-13 · Analyzed
7.5EPSS 0.002
CVE-2024-4216
XSS vulnerability in /settings/store API response json payload in pgAdmin 4
Published 2024-05-02 · Analyzed
7.4EPSS 0.005
CVE-2024-6238
pgAdmin 4 Installation Directory permission issue
Published 2024-06-25 · Analyzed
7.4EPSS 0.002
CVE-2026-86862
pgAdmin 4: Connection-string injection via the database field in the Restore and Maintenance tools
Published 2026-09-17 · Analyzed
7.1EPSS 0.004
CVE-2026-7817
pgAdmin 4: Local file inclusion and server-side request forgery in LLM API configuration endpoints
Published 2026-05-11 · Analyzed
7.1EPSS 0.003
CVE-2026-17348
pgAdmin 4: Missing authentication decorator on Constraints, preferences, Debugger and Schema Diff routes allows unauthenticated access in SERVER mode (incomplete fix for CVE-2026-12046)
Published 2026-07-31 · Analyzed
6.9EPSS 0.004
CVE-2026-7820
pgAdmin 4: Account-lockout bypass via Flask-Security default /login view
Published 2026-05-11 · Analyzed
6.9EPSS 0.003
CVE-2023-0241
pgAdmin 4 versions prior to v6.19 contains a directory traversal vulnerability. A user of the product may change another user's settings or alter the database.
Published 2023-03-27 · Modified
6.5EPSS 0.088
CVE-2022-0959
A malicious, but authorised and authenticated user can construct an HTTP request using their existing CSRF token and session cookie to manually upload files to any location that the operating system user account under which pgAdmin is running has permission to write.
Published 2022-03-16 · Modified
6.5EPSS 0.010
CVE-2023-22298
Open redirect vulnerability in pgAdmin 4 versions prior to v6.14 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.
Published 2023-01-17 · Modified
6.1EPSS 0.009
1 / 2Next →