VulnSea

pgadmin_4 vulnerabilities

CVEs whose affected-version data names the pgadmin_4 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

8 CVEsRSS

CVE-2026-86864High· 8.8
5d ago

pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument vector as a bare trailing positional argument, without validation

pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument vector as a bare trailing positional argument, without validation. Because pg_dump parses its options…

Twilightpgadmin · pgadmin_4EPSS 0.38%via NVD
CVE-2026-86863Critical· 9.8
5d ago

pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment

pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment. WebserverAuthentication.get_user() read config.WEB…

Midnightpgadmin · pgadmin_4EPSS 0.36%via NVD
CVE-2026-86862Medium· 6.5
5d ago

pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given to pg_restore and psql

pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given to pg_restore and psql. libpq expands a database name containing an equals sign into a full connecti…

Sunlitpgadmin · pgadmin_4EPSS 0.20%via NVD
CVE-2026-86861Medium· 5.9
5d ago

pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with Filemanager.check_access_permission() and then opened the file for writing with a plain open() call

pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with Filemanager.check_access_permission() and then opened the file for writing with a plain open() call. CVE-2026-…

Sunlitpgadmin · pgadmin_4EPSS 0.44%via NVD
CVE-2026-12050Medium· 4.3
3mo ago

SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/{sid})

SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/{sid}). The user-supplied 'value' field was interpolated directly into the SQL string with str.format() instead of being passed as a boun…

Sunlitpgadmin · pgadmin_4EPSS 0.43%via NVD
CVE-2026-12049Medium· 4.3
3mo ago

Open redirect in pgAdmin 4's multi-factor authentication flow

Open redirect in pgAdmin 4's multi-factor authentication flow. The MFA validate and register endpoints honoured the user-supplied 'next' query/form parameter without confirming the target pointed back inside pgAdmin, so an authenticated …

Sunlitpgadmin · pgadmin_4EPSS 0.38%via NVD
CVE-2026-12048Critical· 9.3
3mo ago

Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths

Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL server (ErrorResponse messages, including object names quoted back inside relation-does-not-exist errors and inside E…

Midnightpgadmin · pgadmin_4EPSS 0.27%via NVD
CVE-2026-12047Low· 3.5
3mo ago

HTML injection in pgAdmin 4's cloud deployment module

HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoints under /rds/, /azure/, /google/, and the top-level /cloud/ blueprint propagated AWS / Azure / Google SDK exception…

Sunlitpgadmin · pgadmin_4EPSS 0.22%via NVD
pgadmin_4 vulnerabilities (CVEs) · VulnSea