pgAdmin
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 51 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from March 14, 2022 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →pgAdmin 4: Argument and connection-string injection via the database field in the Backup tool
pgAdmin 4: Authentication bypass via a client-controlled identity header in Webserver authentication mode
pgAdmin 4: Connection-string injection via the database field in the Restore and Maintenance tools
pgAdmin 4: File Manager save_file writes through a symbolic link planted after the containment check
pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)
pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)
pgAdmin 4: Tool permission bypass via backend routes and Socket.IO handlers
pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner
pgAdmin 4: Missing authentication decorator on Constraints, preferences, Debugger and Schema Diff routes allows unauthenticated access in SERVER mode (incomplete fix for CVE-2026-12046)
pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution
Monitor pgAdmin in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.