VulnSea

pgadmin4 has 23 CVEs on record between 2022 and 2026. Disclosures have slowed: 0 in the last 90 days after 8 in the 90 before. The busiest recent month was May 2026 with 8. The median CVSS is 7.4 (high), with 1 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.4
Publish → KEV
Last 90 days
0 prev 8

Products

  • pgadmin4 23
23
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

pgadmin4 vulnerabilities

CVEs affecting pgadmin4, newest first. Open any entry for full detail, references, and exploit status.

23 CVEsRSS

CVE-2026-7813Critical· 9.9
4mo ago

pgAdmin 4 server mode has an authorization vulnerability affecting Server Groups, Servers, Shared Servers, Background Processes, and Debu…

pgAdmin 4 server mode has an authorization vulnerability affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules

Midnightpgadmin4 · pgadmin4EPSS 0.46%via OSV
CVE-2026-7817Medium· 6.5
4mo ago

pgAdmin 4 contains local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities

pgAdmin 4 contains local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities

Sunlitpgadmin4 · pgadmin4EPSS 0.22%via OSV
CVE-2026-7816High· 8.8
4mo ago

pgAdmin 4: OS command injection vulnerability in Import/Export query export

pgAdmin 4: OS command injection vulnerability in Import/Export query export

Twilightpgadmin4 · pgadmin4EPSS 1.4%via OSV
CVE-2026-7820Medium· 6.5
4mo ago

pgAdmin 4: Improper restriction of excessive authentication attempts

pgAdmin 4: Improper restriction of excessive authentication attempts

Sunlitpgadmin4 · pgadmin4EPSS 0.21%via OSV
CVE-2026-7819High· 8.1
4mo ago

pgAdmin 4 File Manager has symbolic-link path traversal

pgAdmin 4 File Manager has symbolic-link path traversal

Twilightpgadmin4 · pgadmin4EPSS 0.36%via OSV
CVE-2026-7815High· 8.8
4mo ago

SQL injection vulnerability in pgAdmin 4 Maintenance Tool

SQL injection vulnerability in pgAdmin 4 Maintenance Tool

Twilightpgadmin4 · pgadmin4EPSS 0.46%via OSV
CVE-2026-7814Medium· 4.8
4mo ago

pgAdmin 4: Stored cross-site scripting (XSS) vulnerability in Browser Tree and Explain Visualizer modules

pgAdmin 4: Stored cross-site scripting (XSS) vulnerability in Browser Tree and Explain Visualizer modules

Sunlitpgadmin4 · pgadmin4EPSS 0.16%via OSV
CVE-2026-7818High· 7.0
4mo ago

pgAdmin 4 has deserialization of untrusted data in its FileBackedSessionManager

pgAdmin 4 has deserialization of untrusted data in its FileBackedSessionManager

Twilightpgadmin4 · pgadmin4EPSS 0.13%via OSV
CVE-2026-1707High· 7.4
7mo ago

pgadmin4 affected by a Restore restriction bypass via key disclosure vulnerability

pgadmin4 affected by a Restore restriction bypass via key disclosure vulnerability

Twilightpgadmin4 · pgadmin4EPSS 0.41%via OSV
CVE-2025-12763Medium· 6.8
10mo ago

pgAdmin 4 has command injection vulnerability on Windows systems

pgAdmin 4 has command injection vulnerability on Windows systems

Sunlitpgadmin4 · pgadmin4EPSS 0.94%via OSV
CVE-2025-12765High· 7.5
10mo ago

pgAdmin has vulnerability in LDAP authentication mechanism that allows bypassing TLS certificate verification

pgAdmin has vulnerability in LDAP authentication mechanism that allows bypassing TLS certificate verification

Twilightpgadmin4 · pgadmin4EPSS 0.22%via OSV
CVE-2025-12764High· 7.5
10mo ago

pgAdmin is affected by an LDAP injection vulnerability

pgAdmin is affected by an LDAP injection vulnerability

Twilightpgadmin4 · pgadmin4EPSS 0.45%via OSV
CVE-2025-9636High· 7.9
1y ago

pgadmin4 is affected by a Cross-Origin Opener Policy (COOP) vulnerability

pgadmin4 is affected by a Cross-Origin Opener Policy (COOP) vulnerability

Twilightpgadmin4 · pgadmin4EPSS 0.21%via OSV
CVE-2023-1907High· 8.0
1y ago

pgAdmin has Incorrect Default Permissions

pgAdmin has Incorrect Default Permissions

Twilightpgadmin4 · pgadmin4EPSS 0.45%via OSV
CVE-2024-9014High· 8.6PoC
1y ago

OAuth2 client ID and secret exposed through the web browser

OAuth2 client ID and secret exposed through the web browser

Midnightpgadmin4 · pgadmin4EPSS 9.7%via OSV
CVE-2024-4216High· 7.4
2y ago

pgAdmin Cross-site Scripting vulnerability in /settings/store API response json payload

pgAdmin Cross-site Scripting vulnerability in /settings/store API response json payload

Twilightpgadmin4 · pgadmin4EPSS 0.46%via OSV
CVE-2024-4215High· 7.4
2y ago

pgAdmin is affected by a multi-factor authentication bypass vulnerability

pgAdmin is affected by a multi-factor authentication bypass vulnerability

Twilightpgadmin4 · pgadmin4EPSS 0.63%via OSV
CVE-2024-3116High· 7.4PoC
2y ago

pgAdmin Remote Code Execution (RCE) vulnerability

pgAdmin Remote Code Execution (RCE) vulnerability

Midnightpgadmin4 · pgadmin4EPSS 66%via OSV
CVE-2023-5002Medium· 6.0
3y ago

pgAdmin failed to properly control the server code

pgAdmin failed to properly control the server code

Sunlitpgadmin4 · pgadmin4EPSS 1.5%via OSV
CVE-2023-0241Medium· 6.5
3y ago

pgAdmin 4 vulnerable to directory traversal

pgAdmin 4 vulnerable to directory traversal

Sunlitpgadmin4 · pgadmin4EPSS 8.8%via OSV
CVE-2023-22298Medium· 6.1
3y ago

pgAdmin 4 Open Redirect vulnerability

pgAdmin 4 Open Redirect vulnerability

Sunlitpgadmin4 · pgadmin4EPSS 0.92%via OSV
CVE-2022-4223High· 8.8PoC
3y ago

pgadmin4 vulnerable to Code Injection

pgadmin4 vulnerable to Code Injection

Midnightpgadmin4 · pgadmin4EPSS 80%via OSV
CVE-2022-0959Medium· 6.5
4y ago

pgAdmin 4 Path Traversal vulnerability

pgAdmin 4 Path Traversal vulnerability

Sunlitpgadmin4 · pgadmin4EPSS 0.97%via OSV
pgadmin4 vulnerabilities (CVEs) · VulnSea