CVE Tools

Pgadmin

8 CVEs tracked since 2026. Since May 2026, none of them reached CISA KEV.

Pgadmin CVEs per month

May 2026 to May 2026. Point at a month, or focus the strip and use the arrow keys.
Pgadmin CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2026-0580

Products

The products that kept showing up in Pgadmin's monthly top three, with their CVEs summed over those months.

  1. Pgadmin 481 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Pgadmin.

  1. CVE-2026-86864pgAdmin 4: Argument and connection-string injection via the database field in the Backup tool8.8
  2. CVE-2026-86863pgAdmin 4: Authentication bypass via a client-controlled identity header in Webserver authentication mode9.8
  3. CVE-2026-86862pgAdmin 4: Connection-string injection via the database field in the Restore and Maintenance tools6.5
  4. CVE-2026-86861pgAdmin 4: File Manager save_file writes through a symbolic link planted after the containment check5.9
  5. CVE-2026-17566pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)9.9
  6. CVE-2026-17351pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)9.0
  7. CVE-2026-17350pgAdmin 4: Tool permission bypass via backend routes and Socket.IO handlers5.4
  8. CVE-2026-17349pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner9.6
  9. CVE-2026-17348pgAdmin 4: Missing authentication decorator on Constraints, preferences, Debugger and Schema Diff routes allows unauthenticated access in SERVER mode (incomplete fix for CVE-2026-12046)6.5
  10. CVE-2026-17347pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution7.5
  11. CVE-2026-17346pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views (incomplete fix for CVE-2026-12044)8.8
  12. CVE-2026-12049pgAdmin 4: Open redirect in multi-factor authentication flow via unvalidated 'next' parameter4.3
  13. CVE-2026-12048pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-parser9.3
  14. CVE-2026-12047pgAdmin 4: HTML injection in cloud verify_credentials / deploy endpoints via unsanitised SDK exception text3.5
  15. CVE-2026-12046pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code execution9.0

The record

Peak rank
#173 in May 2026
Busiest month shown
May 2026, 8 CVEs
Months with a KEV entry
0 since May 2026
Monthly snapshots
1 since 2026
Pgadmin's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store