Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

pgAdmin 4 — Vulnerabilities & Security Advisories 31

All 31 CVE vulnerabilities found in pgAdmin 4, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for the vendor pgAdmin, the product pgAdmin 4, focusing on the weakness type associated with its software architecture. It compiles known security flaws, misconfigurations, and implementation errors discovered within the pgAdmin 4 application, covering vulnerabilities reported and published from its initial releases through the most recent updates. By visiting this section, you can track the vendor's security advisories to stay informed about critical patches and mitigations, gain a deeper understanding of the specific weakness classes that affect database administration tools, and review the product's comprehensive vulnerability history to assess long-term security stability. The collection includes details on how these issues impact confidentiality, integrity, and availability, providing context for developers and system administrators alike. Understanding the timeline and nature of these defects helps in prioritizing remediation efforts and applying necessary configurations to harden the environment. This resource serves as a centralized reference point for evaluating risk exposure related to pgAdmin 4, facilitating better decision-making regarding upgrade paths and security posture adjustments without relying on fragmented external sources.

Vendor: pgAdmin Project

CVE IDTitleCVSSSeverityPublished
CVE-2026-12049 pgAdmin 4: Open redirect in multi-factor authentication flow via unvalidated 'next' parameter CWE-601 4.3 Medium2026-06-18
CVE-2026-12048 pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-parser CWE-79 9.3 Critical2026-06-18
CVE-2026-12047 pgAdmin 4: HTML injection in cloud verify_credentials / deploy endpoints via unsanitised SDK exception text CWE-79 3.5 Low2026-06-18
CVE-2026-12046 pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code execution CWE-306 9.0 Critical2026-06-18
CVE-2026-12045 pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code execution CWE-89 9.0 Critical2026-06-18
CVE-2026-12050 pgAdmin 4: SQL injection in named restore point endpoint CWE-89 4.3 Medium2026-06-18
CVE-2026-12044 pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog templates CWE-89 8.8 High2026-06-18
CVE-2026-7820 pgAdmin 4: Account-lockout bypass via Flask-Security default /login view 6.5 Medium2026-05-11
CVE-2026-7819 pgAdmin 4: Symbolic-link path traversal in File Manager allows arbitrary file write 8.1 High2026-05-11
CVE-2026-7818 pgAdmin 4: Unsafe deserialization (CWE-502) in file-backed session manager leads to remote code execution 7.0 High2026-05-11
CVE-2026-7816 pgAdmin 4: OS command injection in Import/Export query export via psql metacommand breakout 8.8 High2026-05-11
CVE-2026-7817 pgAdmin 4: Local file inclusion and server-side request forgery in LLM API configuration endpoints 6.5 Medium2026-05-11
CVE-2026-7815 pgAdmin 4: SQL injection in Maintenance tool option values leading to remote code execution 8.8 High2026-05-11
CVE-2026-7814 pgAdmin 4: Stored XSS via crafted PostgreSQL object names in Browser Tree and Explain Visualizer 4.8 Medium2026-05-11
CVE-2026-7813 pgAdmin 4: Cross-user data access and shared-server privilege escalation in server mode 9.9 Critical2026-05-11
CVE-2026-1707 Restore restriction bypass via key disclosure vulnerability (pgAdmin 4) 7.4 High2026-02-05
CVE-2025-13780 Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4) 9.1 Critical2025-12-11
CVE-2025-12764 pgAdmin 4: LDAP injection vulnerability in LDAP authentication flow. 7.5 High2025-11-13
CVE-2025-12765 pgAdmin 4: LDAP authentication flow vulnerable to TLS certificate verification bypass. 7.5 High2025-11-13
CVE-2025-12763 Command injection vulnerability allowing arbitrary command execution on Windows 6.8 Medium2025-11-13
CVE-2025-12762 Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4) 9.1 Critical2025-11-13
CVE-2025-9636 Cross-Origin Opener Policy Vulnerability in pgAdmin 4 7.9 High2025-09-04
CVE-2025-2946 Cross-Site Vulnerability(XSS) due to arbitrary HTML/JavaScript gets executed while query result rendering in Query Tool and View/Edit Data Tool of pgAdmin 4 9.1 Critical2025-04-03
CVE-2025-2945 pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment 9.9 Critical2025-04-03
CVE-2024-9014 OAuth2 client id and secret exposed through the web browser in pgAdmin 4 9.9 Critical2024-09-23
CVE-2024-6238 pgAdmin 4 Installation Directory permission issue 7.4 High2024-06-25
CVE-2024-4216 XSS vulnerability in /settings/store API response json payload in pgAdmin 4 7.4 High2024-05-02
CVE-2024-4215 The Multi Factor Authentication bypass vulnerability in pgAdmin 4 7.4 High2024-05-02
CVE-2024-3116 Remote Code Execution Vulnerability through the validate binary path API in pgAdmin 4 7.4 High2024-04-04
CVE-2024-2044 Unsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4 9.9 Critical2024-03-07

All 31 known CVE vulnerabilities affecting pgAdmin 4 with full Chinese analysis, references, and POCs where available.