pgadmin-org
Databasesoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting pgadmin-org.
- CVE-2026-17566pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)9.9
- CVE-2026-17351pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)9.0
- CVE-2026-17350pgAdmin 4: Tool permission bypass via backend routes and Socket.IO handlers5.4
- CVE-2026-17349pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner9.6
- CVE-2026-17348pgAdmin 4: Missing authentication decorator on Constraints, preferences, Debugger and Schema Diff routes allows unauthenticated access in SERVER mode (incomplete fix for CVE-2026-12046)6.5
- CVE-2026-17347pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution7.5
- CVE-2026-17346pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views (incomplete fix for CVE-2026-12044)8.8
- CVE-2026-12049pgAdmin 4: Open redirect in multi-factor authentication flow via unvalidated 'next' parameter4.3
- CVE-2026-12048pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-parser9.3
- CVE-2026-12047pgAdmin 4: HTML injection in cloud verify_credentials / deploy endpoints via unsanitised SDK exception text3.5
- CVE-2026-12046pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code execution9.0
- CVE-2026-12045pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code execution9.0
- CVE-2026-12050pgAdmin 4: SQL injection in named restore point endpoint4.3
- CVE-2026-12044pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog templates8.8
- CVE-2026-7820pgAdmin 4: Account-lockout bypass via Flask-Security default /login view6.5