Pgadmin 4 vulnerabilities
46 known vulnerabilities affecting pgadmin/pgadmin_4.
Total CVEs
46
CISA KEV
0
Public exploits
5
Exploited in wild
1
Severity breakdown
CRITICAL9HIGH19MEDIUM18
Vulnerabilities
Page 3 of 3
CVE-2026-12047P4MEDIUMCVSS 5.4≥ 6.6, < 9.162026-06-19
CVE-2026-12047 [MEDIUM] CWE-79 CVE-2026-12047: HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and
HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoints under /rds/, /azure/, /google/, and the top-level /cloud/ blueprint propagated AWS / Azure / Google SDK exception text — and the related file-resolution and database-commit exception text — into the JSON response body (the info a
nvd
CVE-2023-22298P4MEDIUMCVSS 6.1≥ 4.0, < 6.142023-01-17
CVE-2023-22298 [MEDIUM] CWE-601 CVE-2023-22298: Open redirect vulnerability in pgAdmin 4 versions prior to v6.14 allows a remote unauthenticated att
Open redirect vulnerability in pgAdmin 4 versions prior to v6.14 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.
nvd
CVE-2024-6238P4MEDIUMCVSS 5.3fixed in 8.92024-06-25
CVE-2024-6238 [MEDIUM] CWE-276 CVE-2024-6238: pgAdmin <= 8.8 has an installation Directory permission issue. Because of this issue, attackers can
pgAdmin <= 8.8 has an installation Directory permission issue. Because of this issue, attackers can gain unauthorised access to the installation directory on the Debian or RHEL 8 platforms.
nvd
CVE-2024-4216P4MEDIUMCVSS 5.4fixed in 8.62024-05-02
CVE-2024-4216 [MEDIUM] CWE-79 CVE-2024-4216: pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This v
pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end.
nvd
CVE-2025-2946P4MEDIUMCVSS 6.1≤ 9.12025-04-03
CVE-2025-2946 [MEDIUM] CWE-79 CVE-2025-2946: pgAdmin <= 9.1 is affected by a security vulnerability with Cross-Site Scripting(XSS). If attackers
pgAdmin <= 9.1 is affected by a security vulnerability with Cross-Site Scripting(XSS). If attackers execute any arbitrary HTML/JavaScript in a user's browser through query result rendering, then HTML/JavaScript runs on the browser.
nvd
CVE-2026-7814P4MEDIUMCVSS 4.8≥ 6.9, < 9.152026-05-11
CVE-2026-7814 [MEDIUM] CWE-79 CVE-2026-7814: Stored cross-site scripting (XSS) vulnerability in pgAdmin 4 Browser Tree and Explain Visualizer mod
Stored cross-site scripting (XSS) vulnerability in pgAdmin 4 Browser Tree and Explain Visualizer modules.
User-controlled PostgreSQL object names (database, schema, table, column, etc.) were assigned to DOM elements via innerHTML, allowing crafted object names containing HTML markup to execute attacker-supplied JavaScript in the browser of any pgAdmin
nvd
← Previous3 / 3