Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

pgAdmin 4 — Vulnerabilities & Security Advisories 38

All 38 CVE vulnerabilities found in pgAdmin 4, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for the vendor pgAdmin, the product pgAdmin 4, focusing on the weakness type associated with its software architecture. It compiles known security flaws, misconfigurations, and implementation errors discovered within the pgAdmin 4 application, covering vulnerabilities reported and published from its initial releases through the most recent updates. By visiting this section, you can track the vendor's security advisories to stay informed about critical patches and mitigations, gain a deeper understanding of the specific weakness classes that affect database administration tools, and review the product's comprehensive vulnerability history to assess long-term security stability. The collection includes details on how these issues impact confidentiality, integrity, and availability, providing context for developers and system administrators alike. Understanding the timeline and nature of these defects helps in prioritizing remediation efforts and applying necessary configurations to harden the environment. This resource serves as a centralized reference point for evaluating risk exposure related to pgAdmin 4, facilitating better decision-making regarding upgrade paths and security posture adjustments without relying on fragmented external sources.

Vendor: pgAdmin Project

CVE IDTitleCVSSSeverityPublished
CVE-2026-17566 pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780) CWE-78 9.9 Critical2026-07-31
CVE-2026-17351 pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045) CWE-89 9.0 Critical2026-07-31
CVE-2026-17350 pgAdmin 4: Tool permission bypass via backend routes and Socket.IO handlers CWE-862 5.4 Medium2026-07-31
CVE-2026-17349 pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner CWE-639 9.6 Critical2026-07-31
CVE-2026-17348 pgAdmin 4: Missing authentication decorator on Constraints, preferences, Debugger and Schema Diff routes allows unauthenticated access in SERVER mode (incomplete fix for CVE-2026-12046) CWE-306 6.5 Medium2026-07-31
CVE-2026-17347 pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution CWE-78 7.5 High2026-07-31
CVE-2026-17346 pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views (incomplete fix for CVE-2026-12044) CWE-89 8.8 High2026-07-31
CVE-2026-12049 pgAdmin 4: Open redirect in multi-factor authentication flow via unvalidated 'next' parameter CWE-601 4.3 Medium2026-06-18
CVE-2026-12048 pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-parser CWE-79 9.3 Critical2026-06-18
CVE-2026-12047 pgAdmin 4: HTML injection in cloud verify_credentials / deploy endpoints via unsanitised SDK exception text CWE-79 3.5 Low2026-06-18
CVE-2026-12046 pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code execution CWE-306 9.0 Critical2026-06-18
CVE-2026-12045 pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code execution CWE-89 9.0 Critical2026-06-18
CVE-2026-12050 pgAdmin 4: SQL injection in named restore point endpoint CWE-89 4.3 Medium2026-06-18
CVE-2026-12044 pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog templates CWE-89 8.8 High2026-06-18
CVE-2026-7820 pgAdmin 4: Account-lockout bypass via Flask-Security default /login view 6.5 Medium2026-05-11
CVE-2026-7819 pgAdmin 4: Symbolic-link path traversal in File Manager allows arbitrary file write 8.1 High2026-05-11
CVE-2026-7818 pgAdmin 4: Unsafe deserialization (CWE-502) in file-backed session manager leads to remote code execution 7.0 High2026-05-11
CVE-2026-7817 pgAdmin 4: Local file inclusion and server-side request forgery in LLM API configuration endpoints 6.5 Medium2026-05-11
CVE-2026-7816 pgAdmin 4: OS command injection in Import/Export query export via psql metacommand breakout 8.8 High2026-05-11
CVE-2026-7815 pgAdmin 4: SQL injection in Maintenance tool option values leading to remote code execution 8.8 High2026-05-11
CVE-2026-7813 pgAdmin 4: Cross-user data access and shared-server privilege escalation in server mode 9.9 Critical2026-05-11
CVE-2026-7814 pgAdmin 4: Stored XSS via crafted PostgreSQL object names in Browser Tree and Explain Visualizer 4.8 Medium2026-05-11
CVE-2026-1707 Restore restriction bypass via key disclosure vulnerability (pgAdmin 4) 7.4 High2026-02-05
CVE-2025-13780 Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4) 9.1 Critical2025-12-11
CVE-2025-12764 pgAdmin 4: LDAP injection vulnerability in LDAP authentication flow. 7.5 High2025-11-13
CVE-2025-12765 pgAdmin 4: LDAP authentication flow vulnerable to TLS certificate verification bypass. 7.5 High2025-11-13
CVE-2025-12763 Command injection vulnerability allowing arbitrary command execution on Windows 6.8 Medium2025-11-13
CVE-2025-12762 Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4) 9.1 Critical2025-11-13
CVE-2025-9636 Cross-Origin Opener Policy Vulnerability in pgAdmin 4 7.9 High2025-09-04
CVE-2025-2946 Cross-Site Vulnerability(XSS) due to arbitrary HTML/JavaScript gets executed while query result rendering in Query Tool and View/Edit Data Tool of pgAdmin 4 9.1 Critical2025-04-03

All 38 known CVE vulnerabilities affecting pgAdmin 4 with full Chinese analysis, references, and POCs where available.