Vulnerability index

Browse CVEs

43 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pgadmin 4 CRITICAL 9.9
CVE-2026-17566

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passi…

Fix: 9.18+
Fix from $2,300 2026-07-31
Pgadmin 4 CRITICAL 9.6
CVE-2026-17349

/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones th…

Fix: 9.17+
Fix from $2,300 2026-07-31
Pgadmin 4 CRITICAL 9.0
CVE-2026-17351

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlpar…

Fix: 9.17+
Fix from $2,300 2026-07-31
Pgadmin 4 HIGH 8.8
CVE-2026-17347

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption…

Fix: 9.17+
Fix from $1,950 2026-07-31
Pgadmin 4 MEDIUM 6.5
CVE-2026-17348

In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles…

Fix: 9.17+
Fix from $1,600 2026-07-31
Pgadmin 4 MEDIUM 5.4
CVE-2026-17350

The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce its permission check consist…

Fix: 9.17+
Fix from $1,600 2026-07-31
Pgadmin 4 HIGH 8.8
CVE-2026-17346

The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but miss…

Fix: 9.17+
Fix from $1,950 2026-07-31
Pgadmin 4 HIGH 8.8
CVE-2026-12050

SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/{sid}). The user-supplied 'value' field was inter…

Fix: 9.16+
Fix from $1,950 2026-06-19
Pgadmin 4 MEDIUM 6.1
CVE-2026-12049

Open redirect in pgAdmin 4's multi-factor authentication flow. The MFA validate and register endpoints honoured the user-supplied 'next' query/form p…

Fix: 9.16+
Fix from $1,600 2026-06-19
Pgadmin 4 MEDIUM 5.4
CVE-2026-12047

HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoints under /rds/, /azure/, /go…

Fix: 9.16+
Fix from $1,600 2026-06-19
Pgadmin 4 MEDIUM 5.4
CVE-2026-12048

Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL server (ErrorResponse message…

Fix: 9.16+
Fix from $1,600 2026-06-19
Pgadmin 4 CRITICAL 9.0
CVE-2026-12046

Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/updat…

Fix: 9.16+
Fix from $2,300 2026-06-19
Pgadmin 4 HIGH 8.8
CVE-2026-12044

SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<description>'`` for a user-supplied description field. The…

Fix: 9.16+
Fix from $1,950 2026-06-19
Pgadmin 4 HIGH 8.8
CVE-2026-12045

Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute …

Fix: 9.16+
Fix from $1,950 2026-06-19
Pgadmin 4 HIGH 8.1
CVE-2026-7819

Symbolic-link path traversal (CWE-61, CWE-22) in pgAdmin 4 File Manager. check_access_permission used os.path.abspath, which resolves '..' but does …

Fix: 9.15+
Fix from $1,950 2026-05-11
Pgadmin 4 MEDIUM 6.5
CVE-2026-7820

Improper restriction of excessive authentication attempts (CWE-307) in pgAdmin 4. pgAdmin enforces MAX_LOGIN_ATTEMPTS only inside its custom /authen…

Fix: 9.15+
Fix from $1,600 2026-05-11
Pgadmin 4 HIGH 8.8
CVE-2026-7816

OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export query export. User-supplied input was interpolated directly into a psql \copy…

Fix: 9.15+
Fix from $1,950 2026-05-11
Pgadmin 4 HIGH 7.8
CVE-2026-7818

Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager. The session manager performed unsafe deserialization of session-f…

Fix: 9.15+
Fix from $1,950 2026-05-11
Pgadmin 4 MEDIUM 6.5
CVE-2026-7817

Local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities in pgAdmin 4 LLM API configuration endpoints. User-supplied api_ke…

Fix: 9.15+
Fix from $1,600 2026-05-11
Pgadmin 4 CRITICAL 9.9
CVE-2026-7813

Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules. M…

Fix: 9.15+
Fix from $2,300 2026-05-11
Pgadmin 4 HIGH 8.8
CVE-2026-7815

SQL injection vulnerability in pgAdmin 4 Maintenance Tool. Four user-supplied JSON fields (buffer_usage_limit, vacuum_parallel, vacuum_index_cleanup…

Fix: 9.15+
Fix from $1,950 2026-05-11
Pgadmin 4 MEDIUM 6.3
CVE-2026-1707

pgAdmin versions 9.11 are affected by a Restore restriction bypass via key disclosure vulnerability that occurs when running in server mode and perfo…

Mitigation only
Fix from $1,600 2026-02-05
Pgadmin 4 HIGH 8.8
CVE-2025-13780

pgAdmin versions up to 9.10 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restor…

Fix: after 9.10
Fix from $1,950 2025-12-11
Pgadmin 4 HIGH 7.4
CVE-2025-12765

pgAdmin <= 9.9  is affected by a vulnerability in the LDAP authentication mechanism allows bypassing TLS certificate verification.

Fix: 9.10+
Fix from $1,950 2025-11-13
Pgadmin 4 CRITICAL 9.8
CVE-2025-12762EPSS 12%

pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restore…

Fix: 9.10+
Fix from $2,300 2025-11-13
Pgadmin 4 HIGH 8.8
CVE-2025-12763

pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused by the use of shell=True duri…

Fix: 9.10+
Fix from $1,950 2025-11-13
Pgadmin 4 HIGH 7.5
CVE-2025-12764

pgAdmin <= 9.9  is affected by an LDAP injection vulnerability in the LDAP authentication flow that allows an attacker to inject special LDAP charact…

Fix: 9.10+
Fix from $1,950 2025-11-13
Pgadmin 4 HIGH 7.9
CVE-2025-9636

pgAdmin <= 9.7 is affected by a Cross-Origin Opener Policy (COOP) vulnerability. This vulnerability allows an attacker to manipulate the OAuth flow,…

Fix: after 9.7
Fix from $1,950 2025-09-04
Pgadmin 4 HIGH 8.8
CVE-2025-2945EPSS 47%

Remote Code Execution security vulnerability in pgAdmin 4 (Query Tool and Cloud Deployment modules). The vulnerability is associated with the 2 POS…

Fix: 9.2+
Fix from $1,950 2025-04-03
Pgadmin 4 MEDIUM 6.1
CVE-2025-2946

pgAdmin <= 9.1 is affected by a security vulnerability with Cross-Site Scripting(XSS). If attackers execute any arbitrary HTML/JavaScript in a user's…

Fix: after 9.1
Fix from $1,600 2025-04-03