LIVE · cybersecurity feed
Live wire
vendor

Pgadmin

14 CVEs published in the last four months. Exploited flaws first.

Critical7
High7
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-78139.9criticalpgadmin 4Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background P117d ago
CVE-2026-175669.9criticalpgadmin 4pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL qu36d ago
CVE-2026-173499.6criticalpgadmin 4/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the 36d ago
CVE-2026-120489.3criticalpgadmin 4Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths.79d ago
CVE-2026-120469criticalpgadmin 4Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /s79d ago
CVE-2026-173519criticalpgadmin 4The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_36d ago
CVE-2026-120459criticalpgadmin 4Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content t79d ago
CVE-2026-78158.8highpgadmin 4SQL injection vulnerability in pgAdmin 4 Maintenance Tool.117d ago
CVE-2026-120448.8highpgadmin 4SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ...79d ago
CVE-2026-173468.8highpgadmin 4The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pg36d ago
CVE-2026-78168.8highpgadmin 4OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export query export.117d ago
CVE-2026-78198.1highpgadmin 4Symbolic-link path traversal (CWE-61, CWE-22) in pgAdmin 4 File Manager.117d ago
CVE-2026-173477.5highpgadmin 4The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command36d ago
CVE-2026-78187highpgadmin 4Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager.117d ago

Filter the full tracker by Pgadmin