CVEs we hold for Pgadmin.org
Records whose assigning authority named Pgadmin.org as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-86864pgAdmin 4: Argument and connection-string injection via the database field in the Backup toolpgadmin.org pgAdmin 4
CVE-2026-86863pgAdmin 4: Authentication bypass via a client-controlled identity header in Webserver authentication modepgadmin.org pgAdmin 4
CVE-2026-86862pgAdmin 4: Connection-string injection via the database field in the Restore and Maintenance toolspgadmin.org pgAdmin 4
CVE-2026-86861pgAdmin 4: File Manager save_file writes through a symbolic link planted after the containment checkpgadmin.org pgAdmin 4
CVE-2026-7820pgAdmin 4: Account-lockout bypass via Flask-Security default /login viewpgadmin.org pgAdmin 4
CVE-2026-7819pgAdmin 4: Symbolic-link path traversal in File Manager allows arbitrary file writepgadmin.org pgAdmin 4
CVE-2026-7818pgAdmin 4: Unsafe deserialization (CWE-502) in file-backed session manager leads to remote code executionpgadmin.org pgAdmin 4
CVE-2026-7817pgAdmin 4: Local file inclusion and server-side request forgery in LLM API configuration endpointspgadmin.org pgAdmin 4
CVE-2026-7816pgAdmin 4: OS command injection in Import/Export query export via psql metacommand breakoutpgadmin.org pgAdmin 4
CVE-2026-7815pgAdmin 4: SQL injection in Maintenance tool option values leading to remote code executionpgadmin.org pgAdmin 4
CVE-2026-7814pgAdmin 4: Stored XSS via crafted PostgreSQL object names in Browser Tree and Explain Visualizerpgadmin.org pgAdmin 4
CVE-2026-7813pgAdmin 4: Cross-user data access and shared-server privilege escalation in server modepgadmin.org pgAdmin 4
CVE-2026-17566pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to…pgadmin.org pgAdmin 4
CVE-2026-17351pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for…pgadmin.org pgAdmin 4
CVE-2026-17350pgAdmin 4: Tool permission bypass via backend routes and Socket.IO handlerspgadmin.org pgAdmin 4
CVE-2026-17349pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-ownerpgadmin.org pgAdmin 4
CVE-2026-17348pgAdmin 4: Missing authentication decorator on Constraints, preferences, Debugger and Schema Diff routes allows…pgadmin.org pgAdmin 4
CVE-2026-17347pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitutionpgadmin.org pgAdmin 4
CVE-2026-17346pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views…pgadmin.org pgAdmin 4
CVE-2026-1707Restore restriction bypass via key disclosure vulnerability (pgAdmin 4)pgadmin.org pgAdmin 4
CVE-2026-12049pgAdmin 4: Open redirect in multi-factor authentication flow via unvalidated 'next' parameterpgadmin.org pgAdmin 4
CVE-2026-12048pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-parserpgadmin.org pgAdmin 4
CVE-2026-12047pgAdmin 4: HTML injection in cloud verify_credentials / deploy endpoints via unsanitised SDK exception textpgadmin.org pgAdmin 4
CVE-2026-12046pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code…pgadmin.org pgAdmin 4
CVE-2026-12045pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code executionpgadmin.org pgAdmin 4
CVE-2026-12044pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog templatespgadmin.org pgAdmin 4
CVE-2025-2946Cross-Site Vulnerability(XSS) due to arbitrary HTML/JavaScript gets executed while query result rendering in Query Tool…pgadmin.org pgAdmin 4
CVE-2025-2945pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deploymentpgadmin.org pgAdmin 4
CVE-2025-13780Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)pgadmin.org pgAdmin 4
CVE-2025-12765pgAdmin 4: LDAP authentication flow vulnerable to TLS certificate verification bypass.pgadmin.org pgAdmin 4
CVE-2025-12764pgAdmin 4: LDAP injection vulnerability in LDAP authentication flow.pgadmin.org pgAdmin 4
CVE-2025-12763Command injection vulnerability allowing arbitrary command execution on Windowspgadmin.org pgAdmin 4
CVE-2025-12762Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)pgadmin.org pgAdmin 4
CVE-2024-9014OAuth2 client id and secret exposed through the web browser in pgAdmin 4pgadmin.org pgAdmin 4
CVE-2024-4216XSS vulnerability in /settings/store API response json payload in pgAdmin 4pgadmin.org pgAdmin 4
CVE-2024-3116Remote Code Execution Vulnerability through the validate binary path API in pgAdmin 4pgadmin.org pgAdmin 4
CVE-2024-2044Unsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4pgadmin.org pgAdmin 4
41 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.