Where
-Infinity
0

pgAdmin pgAdmin 4pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)

Risk 77
Severity
9.4
First published (updated )

pgAdmin pgAdmin 4pgAdmin 4: Tool permission bypass via backend routes and Socket.IO handlers

Risk 34
Severity
5.3
First published (updated )

pgAdmin pgAdmin 4pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner

Risk 68
Severity
9.3
First published (updated )

pgAdmin pgAdmin 4pgAdmin 4: Missing authentication decorator on Constraints, preferences, Debugger and Schema Diff routes allows unauthenticated access in SERVER mode (incomplete fix for CVE-2026-12046)

Risk 41
Severity
6.9
First published (updated )

pgAdmin pgAdmin 4pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution

Risk 79
Severity
7.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pgAdmin pgAdmin 4pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views (incomplete fix for CVE-2026-12044)

Risk 79
Severity
8.7
First published (updated )

pgAdmin pgAdmin 4pgAdmin 4: Open redirect in multi-factor authentication flow via unvalidated 'next' parameter

Risk 38
Severity
5.3
First published (updated )

pgAdmin pgAdmin 4pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-parser

Risk 67
Severity
9.3
First published (updated )

pgAdmin pgAdmin 4pgAdmin 4: HTML injection in cloud verify_credentials / deploy endpoints via unsanitised SDK exception text

Risk 34
Severity
4.8
First published (updated )

pgAdmin pgAdmin 4pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code execution

Risk 80
Severity
9.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pgAdmin pgAdmin 4pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code execution

Risk 77
Severity
9.4
First published (updated )

pgAdmin pgAdmin 4pgAdmin 4: SQL injection in named restore point endpoint

Risk 79
Severity
5.3
First published (updated )

pgAdmin pgAdmin 4pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog templates

Risk 79
Severity
8.7
First published (updated )

pgAdmin pgAdmin 4pgAdmin 4: Account-lockout bypass via Flask-Security default /login view

Risk 29
Severity
6.9
EPSS
0.04%
First published (updated )

pgAdmin pgAdmin 4pgAdmin 4: Unsafe deserialization (CWE-502) in file-backed session manager leads to remote code execution

Risk 51
Severity
7.3
EPSS
0.29%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pgAdmin pgAdmin 4pgAdmin 4: Symbolic-link path traversal in File Manager allows arbitrary file write

Risk 43
Severity
7.2
EPSS
0.04%
First published (updated )

pgAdmin pgAdmin 4pgAdmin 4: Local file inclusion and server-side request forgery in LLM API configuration endpoints

Risk 29
Severity
7.1
EPSS
0.03%
First published (updated )

pgAdmin pgAdmin 4pgAdmin 4: OS command injection in Import/Export query export via psql metacommand breakout

Risk 56
Severity
8.7
EPSS
0.13%
First published (updated )

pgAdmin pgAdmin 4pgAdmin 4: SQL injection in Maintenance tool option values leading to remote code execution

Risk 56
Severity
8.7
EPSS
0.04%
First published (updated )

pgAdmin pgAdmin 4pgAdmin 4: Cross-user data access and shared-server privilege escalation in server mode

Risk 59
Severity
9.4
EPSS
0.06%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pgAdmin pgAdmin 4Cross-Origin Opener Policy Vulnerability in pgAdmin 4

Risk 48
Severity
7.9
EPSS
0.03%
First published (updated )

pgAdmin pgAdmin 4pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment

Risk 89
Severity
10
First published (updated )

pgAdmin pgAdmin 4pgAdmin 4 Installation Directory permission issue

Risk 37
Severity
7.4
EPSS
0.04%
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203