pgadmin4 has 23 CVEs on record between 2022 and 2026. Disclosures have slowed: 0 in the last 90 days after 8 in the 90 before. The busiest recent month was May 2026 with 8. The median CVSS is 7.4 (high), with 1 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.4
- Publish → KEV
- —
- Last 90 days
- 0 prev 8
Products
- pgadmin4 23
Worst active — by depth score
CVE-2022-4223High· 8.8pgadmin4 vulnerable to Code Injection76CVE-2024-3116High· 7.4pgAdmin Remote Code Execution (RCE) vulnerability66CVE-2024-9014High· 8.6OAuth2 client ID and secret exposed through the web browser61CVE-2026-7813Critical· 9.9pgAdmin 4 server mode has an authorization vulnerability affecting Server Groups, Servers, Shared Servers, Background Processes, and Debu…55CVE-2026-7816High· 8.8pgAdmin 4: OS command injection vulnerability in Import/Export query export49
pgadmin4 vulnerabilities
CVEs affecting pgadmin4, newest first. Open any entry for full detail, references, and exploit status.
23 CVEsRSS
CVE-2026-7813Critical· 9.9pgAdmin 4 server mode has an authorization vulnerability affecting Server Groups, Servers, Shared Servers, Background Processes, and Debu…
pgAdmin 4 server mode has an authorization vulnerability affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules
CVE-2026-7817Medium· 6.5pgAdmin 4 contains local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities
pgAdmin 4 contains local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities
CVE-2026-7816High· 8.8pgAdmin 4: OS command injection vulnerability in Import/Export query export
pgAdmin 4: OS command injection vulnerability in Import/Export query export
CVE-2026-7820Medium· 6.5pgAdmin 4: Improper restriction of excessive authentication attempts
pgAdmin 4: Improper restriction of excessive authentication attempts
CVE-2026-7819High· 8.1pgAdmin 4 File Manager has symbolic-link path traversal
pgAdmin 4 File Manager has symbolic-link path traversal
CVE-2026-7815High· 8.8SQL injection vulnerability in pgAdmin 4 Maintenance Tool
SQL injection vulnerability in pgAdmin 4 Maintenance Tool
CVE-2026-7814Medium· 4.8pgAdmin 4: Stored cross-site scripting (XSS) vulnerability in Browser Tree and Explain Visualizer modules
pgAdmin 4: Stored cross-site scripting (XSS) vulnerability in Browser Tree and Explain Visualizer modules
CVE-2026-7818High· 7.0pgAdmin 4 has deserialization of untrusted data in its FileBackedSessionManager
pgAdmin 4 has deserialization of untrusted data in its FileBackedSessionManager
CVE-2026-1707High· 7.4pgadmin4 affected by a Restore restriction bypass via key disclosure vulnerability
pgadmin4 affected by a Restore restriction bypass via key disclosure vulnerability
CVE-2025-12763Medium· 6.8pgAdmin 4 has command injection vulnerability on Windows systems
pgAdmin 4 has command injection vulnerability on Windows systems
CVE-2025-12765High· 7.5pgAdmin has vulnerability in LDAP authentication mechanism that allows bypassing TLS certificate verification
pgAdmin has vulnerability in LDAP authentication mechanism that allows bypassing TLS certificate verification
CVE-2025-12764High· 7.5pgAdmin is affected by an LDAP injection vulnerability
pgAdmin is affected by an LDAP injection vulnerability
CVE-2025-9636High· 7.9pgadmin4 is affected by a Cross-Origin Opener Policy (COOP) vulnerability
pgadmin4 is affected by a Cross-Origin Opener Policy (COOP) vulnerability
CVE-2023-1907High· 8.0pgAdmin has Incorrect Default Permissions
pgAdmin has Incorrect Default Permissions
CVE-2024-9014High· 8.6PoCOAuth2 client ID and secret exposed through the web browser
OAuth2 client ID and secret exposed through the web browser
CVE-2024-4216High· 7.4pgAdmin Cross-site Scripting vulnerability in /settings/store API response json payload
pgAdmin Cross-site Scripting vulnerability in /settings/store API response json payload
CVE-2024-4215High· 7.4pgAdmin is affected by a multi-factor authentication bypass vulnerability
pgAdmin is affected by a multi-factor authentication bypass vulnerability
CVE-2024-3116High· 7.4PoCpgAdmin Remote Code Execution (RCE) vulnerability
pgAdmin Remote Code Execution (RCE) vulnerability
CVE-2023-5002Medium· 6.0pgAdmin failed to properly control the server code
pgAdmin failed to properly control the server code
CVE-2023-0241Medium· 6.5pgAdmin 4 vulnerable to directory traversal
pgAdmin 4 vulnerable to directory traversal
CVE-2023-22298Medium· 6.1pgAdmin 4 Open Redirect vulnerability
pgAdmin 4 Open Redirect vulnerability
CVE-2022-4223High· 8.8PoCpgadmin4 vulnerable to Code Injection
pgadmin4 vulnerable to Code Injection
CVE-2022-0959Medium· 6.5pgAdmin 4 Path Traversal vulnerability
pgAdmin 4 Path Traversal vulnerability