pgadmin.org
Databasesoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting pgadmin.org.
- CVE-2026-12049pgAdmin 4: Open redirect in multi-factor authentication flow via unvalidated 'next' parameter4.3
- CVE-2026-12048pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-parser9.3
- CVE-2026-12047pgAdmin 4: HTML injection in cloud verify_credentials / deploy endpoints via unsanitised SDK exception text3.5
- CVE-2026-12046pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code execution9.0
- CVE-2026-12045pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code execution9.0
- CVE-2026-12050pgAdmin 4: SQL injection in named restore point endpoint4.3
- CVE-2026-12044pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog templates8.8
- CVE-2026-7820pgAdmin 4: Account-lockout bypass via Flask-Security default /login view6.5
- CVE-2026-7818pgAdmin 4: Unsafe deserialization (CWE-502) in file-backed session manager leads to remote code execution7.0
- CVE-2026-7819pgAdmin 4: Symbolic-link path traversal in File Manager allows arbitrary file write8.1
- CVE-2026-7817pgAdmin 4: Local file inclusion and server-side request forgery in LLM API configuration endpoints6.5
- CVE-2026-7815pgAdmin 4: SQL injection in Maintenance tool option values leading to remote code execution8.8
- CVE-2026-7816pgAdmin 4: OS command injection in Import/Export query export via psql metacommand breakout8.8
- CVE-2026-7814pgAdmin 4: Stored XSS via crafted PostgreSQL object names in Browser Tree and Explain Visualizer4.8
- CVE-2026-7813pgAdmin 4: Cross-user data access and shared-server privilege escalation in server mode9.9