📦 Pgadmin 4

by Pgadmin

🔍 What is Pgadmin 4?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-12762

CRITICAL CVSS 9.1 Nov 13, 2025

pgAdmin versions up to 9.9 running in server mode are vulnerable to remote code execution when processing PLAIN-format database dump files during restore operations. Attackers can inject arbitrary com...

CVE-2025-2945

CRITICAL CVSS 9.9 Apr 3, 2025

This CVE describes a critical remote code execution vulnerability in pgAdmin 4 where attacker-controlled input is passed to Python's eval() function. Attackers can execute arbitrary code on the pgAdmi...

CVE-2024-9014

CRITICAL CVSS 9.9 Sep 23, 2024

pgAdmin versions 8.11 and earlier have an OAuth2 authentication vulnerability that could expose client IDs and secrets. This allows attackers to potentially gain unauthorized access to user data throu...

CVE-2024-2044

CRITICAL CVSS 9.9 Mar 7, 2024

pgAdmin versions up to 8.3 contain a path traversal vulnerability in session handling that allows unsafe deserialization of pickle objects, leading to remote code execution. On Windows, unauthenticate...

CVE-2026-1707

HIGH CVSS 7.4 Feb 5, 2026

pgAdmin 9.11 in server mode has a restore restriction bypass vulnerability that allows authenticated attackers to execute arbitrary commands on the host system during restore operations. Attackers can...

CVE-2025-12765

HIGH CVSS 7.5 Nov 13, 2025

pgAdmin versions up to 9.9 have a vulnerability in LDAP authentication that allows attackers to bypass TLS certificate verification. This enables man-in-the-middle attacks where authentication traffic...

CVE-2025-12764

HIGH CVSS 7.5 Nov 13, 2025

pgAdmin versions up to 9.9 have an LDAP injection vulnerability in the authentication flow that allows attackers to inject special LDAP characters in usernames. This can cause denial of service by mak...

CVE-2025-9636

HIGH CVSS 7.9 Sep 4, 2025

pgAdmin versions up to 9.7 have a Cross-Origin Opener Policy vulnerability that allows attackers to manipulate OAuth authentication flows. This could lead to unauthorized account access, account takeo...

CVE-2024-4215

HIGH CVSS 7.4 May 2, 2024

This vulnerability allows attackers who have stolen valid pgAdmin credentials to bypass multi-factor authentication (MFA) protections. Affected systems running pgAdmin 8.5 or earlier are vulnerable, e...

CVE-2024-3116

HIGH CVSS 7.4 Apr 4, 2024

pgAdmin versions up to 8.4 contain a remote code execution vulnerability in the validate binary path API. Attackers can exploit this to execute arbitrary code on the server hosting pgAdmin, potentiall...

CVE-2025-12763

MEDIUM CVSS 6.8 Nov 13, 2025

pgAdmin 4 on Windows systems contains a command injection vulnerability that allows attackers to execute arbitrary system commands through specially crafted file paths during backup/restore operations...

CVE-2023-0241

MEDIUM CVSS 6.5 Mar 27, 2023

CVE-2023-0241 is a directory traversal vulnerability in pgAdmin 4 that allows authenticated users to access or modify files outside the intended directory. This affects all pgAdmin 4 users running ver...