pgadmin records
48 published records for vendor pgadmin.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 3 · 6.3%
- Pre-auth RCE
- 5
- With a fix record
- 87.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-306 Missing Authentication for Critical Function2
- CWE-284 Improper Access Control2
The weakness classes this vendor ships most often: where to look.
CWEAll records
48 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
63This week | CVE-2024-2044Weaponized | Unsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4pgadmin · pgadmin 4 · CWE-31 | Critical9.9 | — | 79.5% | Mar 7, 2024 |
59Plan | CVE-2022-4223Proof of concept | The pgAdmin server includes an HTTP API that is intended to be used to validate the path a user selects to external PostgreSQL utilities sucpgadmin · pgadmin 4 · CWE-94 | High8.8 | — | 80.1% | Dec 13, 2022 |
59Plan | CVE-2024-3116Weaponized | Remote Code Execution Vulnerability through the validate binary path API in pgAdmin 4pgadmin · pgadmin 4 · CWE-77 | Critical9.8 | — | 65.6% | Apr 4, 2024 |
52Plan | CVE-2025-2945Weaponized | pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deploymentpgadmin · pgadmin 4 · CWE-94 | High8.8 | — | 56.3% | Apr 3, 2025 |
43Plan | CVE-2025-12762Proof of concept | Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)pgadmin · pgadmin 4 · CWE-94 | Critical9.8 | — | 12.7% | Nov 13, 2025 |
38Monitor | CVE-2026-12046No exploit | pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code executionpgadmin · pgadmin 4 · CWE-306 | Critical9.5 | — | 1.0% | Jun 18, 2026 |
37Monitor | CVE-2026-17566Proof of concept | pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)pgadmin · pgadmin 4 · CWE-78 | Critical9.4 | — | 0.7% | Jul 31, 2026 |
37Monitor | CVE-2026-12045No exploit | pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code executionpgadmin · pgadmin 4 · CWE-77 | Critical9.4 | — | 0.7% | Jun 18, 2026 |
37Monitor | CVE-2026-7813No exploit | pgAdmin 4: Cross-user data access and shared-server privilege escalation in server modepgadmin · pgadmin 4 · CWE-284 | Critical9.4 | — | 0.7% | May 11, 2026 |
37Monitor | CVE-2026-86863No exploit | pgAdmin 4: Authentication bypass via a client-controlled identity header in Webserver authentication modepgadmin · pgadmin 4 · CWE-290 | Critical9.3 | — | 0.6% | Sep 17, 2026 |
37Monitor | CVE-2026-17351Proof of concept | pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)pgadmin · pgadmin 4 · CWE-89 | Critical9.4 | — | 0.5% | Jul 31, 2026 |
37Monitor | CVE-2026-17349No exploit | pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-ownerpgadmin · pgadmin 4 · CWE-522 | Critical9.3 | — | 0.4% | Jul 31, 2026 |
37Monitor | CVE-2026-12048No exploit | pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-parserpgadmin · pgadmin 4 · CWE-79 | Critical9.3 | — | 0.3% | Jun 18, 2026 |
36Monitor | CVE-2023-5002No exploit | Pgadmin4: remote code execution by an authenticated userpgadmin · pgadmin 4 · CWE-78 | High8.8 | — | 1.8% | Sep 22, 2023 |
35Monitor | CVE-2026-7816No exploit | pgAdmin 4: OS command injection in Import/Export query export via psql metacommand breakoutpgadmin · pgadmin 4 · CWE-78 | High8.7 | — | 2.2% | May 11, 2026 |
35Monitor | CVE-2025-13780Proof of concept | Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)pgadmin · pgadmin 4 · CWE-94 | High8.8 | — | 0.9% | Dec 11, 2025 |
35Monitor | CVE-2025-12763No exploit | Command injection vulnerability allowing arbitrary command execution on Windowspgadmin · pgadmin 4 · CWE-78 | High8.8 | — | 0.9% | Nov 13, 2025 |
35Monitor | CVE-2024-4215No exploit | The Multi Factor Authentication bypass vulnerability in pgAdmin 4pgadmin · pgadmin 4 · CWE-89 | High8.8 | — | 0.6% | May 2, 2024 |
34Monitor | CVE-2026-12044No exploit | pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog templatespgadmin · pgadmin 4 · CWE-89 | High8.7 | — | 0.7% | Jun 18, 2026 |
34Monitor | CVE-2026-7815No exploit | pgAdmin 4: SQL injection in Maintenance tool option values leading to remote code executionpgadmin · pgadmin 4 · CWE-89 | High8.7 | — | 0.6% | May 11, 2026 |
34Monitor | CVE-2026-17346No exploit | pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views (incomplete fix for CVE-2026-12044)pgadmin · pgadmin 4 · CWE-89 | High8.7 | — | 0.6% | Jul 31, 2026 |
34Monitor | CVE-2026-86864No exploit | pgAdmin 4: Argument and connection-string injection via the database field in the Backup toolpgadmin · pgadmin 4 · CWE-22 | High8.7 | — | 0.6% | Sep 17, 2026 |
31Monitor | CVE-2025-9636No exploit | Cross-Origin Opener Policy Vulnerability in pgAdmin 4pgadmin · pgadmin 4 · CWE-346 | High7.9 | — | 0.2% | Sep 4, 2025 |
30Monitor | CVE-2026-17347No exploit | pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitutionpgadmin · pgadmin 4 · CWE-78 | High7.7 | — | 0.7% | Jul 31, 2026 |
30Monitor | CVE-2025-12764No exploit | pgAdmin 4: LDAP injection vulnerability in LDAP authentication flow.pgadmin · pgadmin 4 · CWE-90 | High7.5 | — | 0.4% | Nov 13, 2025 |
- CVE-2024-204463This week
Unsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4
CriticalCVSS 9.9WeaponizedEPSS 79%pgadmin · pgadmin 4Mar 7, 2024
- CVE-2022-422359Plan
The pgAdmin server includes an HTTP API that is intended to be used to validate the path a user selects to external PostgreSQL utilities suc
HighCVSS 8.8Proof of conceptEPSS 80%pgadmin · pgadmin 4Dec 13, 2022
- CVE-2024-311659Plan
Remote Code Execution Vulnerability through the validate binary path API in pgAdmin 4
CriticalCVSS 9.8WeaponizedEPSS 66%pgadmin · pgadmin 4Apr 4, 2024
- CVE-2025-294552Plan
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
HighCVSS 8.8WeaponizedEPSS 56%pgadmin · pgadmin 4Apr 3, 2025
- CVE-2025-1276243Plan
Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)
CriticalCVSS 9.8Proof of conceptEPSS 13%pgadmin · pgadmin 4Nov 13, 2025
- CVE-2026-1204638Monitor
pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code execution
CriticalCVSS 9.5No exploitEPSS 1%pgadmin · pgadmin 4Jun 18, 2026
- CVE-2026-1756637Monitor
pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)
CriticalCVSS 9.4Proof of conceptEPSS 1%pgadmin · pgadmin 4Jul 31, 2026
- CVE-2026-1204537Monitor
pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code execution
CriticalCVSS 9.4No exploitEPSS 1%pgadmin · pgadmin 4Jun 18, 2026
- CVE-2026-781337Monitor
pgAdmin 4: Cross-user data access and shared-server privilege escalation in server mode
CriticalCVSS 9.4No exploitEPSS 1%pgadmin · pgadmin 4May 11, 2026
- CVE-2026-8686337Monitor
pgAdmin 4: Authentication bypass via a client-controlled identity header in Webserver authentication mode
CriticalCVSS 9.3No exploitEPSS 1%pgadmin · pgadmin 4Sep 17, 2026
- CVE-2026-1735137Monitor
pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)
CriticalCVSS 9.4Proof of conceptEPSS 0%pgadmin · pgadmin 4Jul 31, 2026
- CVE-2026-1734937Monitor
pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner
CriticalCVSS 9.3No exploitEPSS 0%pgadmin · pgadmin 4Jul 31, 2026
- CVE-2026-1204837Monitor
pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-parser
CriticalCVSS 9.3No exploitEPSS 0%pgadmin · pgadmin 4Jun 18, 2026
- CVE-2023-500236Monitor
Pgadmin4: remote code execution by an authenticated user
HighCVSS 8.8No exploitEPSS 2%pgadmin · pgadmin 4Sep 22, 2023
- CVE-2026-781635Monitor
pgAdmin 4: OS command injection in Import/Export query export via psql metacommand breakout
HighCVSS 8.7No exploitEPSS 2%pgadmin · pgadmin 4May 11, 2026
- CVE-2025-1378035Monitor
Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)
HighCVSS 8.8Proof of conceptEPSS 1%pgadmin · pgadmin 4Dec 11, 2025
- CVE-2025-1276335Monitor
Command injection vulnerability allowing arbitrary command execution on Windows
HighCVSS 8.8No exploitEPSS 1%pgadmin · pgadmin 4Nov 13, 2025
- CVE-2024-421535Monitor
The Multi Factor Authentication bypass vulnerability in pgAdmin 4
HighCVSS 8.8No exploitEPSS 1%pgadmin · pgadmin 4May 2, 2024
- CVE-2026-1204434Monitor
pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog templates
HighCVSS 8.7No exploitEPSS 1%pgadmin · pgadmin 4Jun 18, 2026
- CVE-2026-781534Monitor
pgAdmin 4: SQL injection in Maintenance tool option values leading to remote code execution
HighCVSS 8.7No exploitEPSS 1%pgadmin · pgadmin 4May 11, 2026
- CVE-2026-1734634Monitor
pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views (incomplete fix for CVE-2026-12044)
HighCVSS 8.7No exploitEPSS 1%pgadmin · pgadmin 4Jul 31, 2026
- CVE-2026-8686434Monitor
pgAdmin 4: Argument and connection-string injection via the database field in the Backup tool
HighCVSS 8.7No exploitEPSS 1%pgadmin · pgadmin 4Sep 17, 2026
- CVE-2025-963631Monitor
Cross-Origin Opener Policy Vulnerability in pgAdmin 4
HighCVSS 7.9No exploitEPSS 0%pgadmin · pgadmin 4Sep 4, 2025
- CVE-2026-1734730Monitor
pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution
HighCVSS 7.7No exploitEPSS 1%pgadmin · pgadmin 4Jul 31, 2026
- CVE-2025-1276430Monitor
pgAdmin 4: LDAP injection vulnerability in LDAP authentication flow.
HighCVSS 7.5No exploitEPSS 0%pgadmin · pgadmin 4Nov 13, 2025