17 Total CVEs
17 AI Analyzed
0 CISA KEV
6 Critical

Profile

0% ended up actively exploited 0 of 17 added to CISA KEV
35% rated critical (CVSS 9.0+) 6 critical, 11 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

16 CVEs in the last 12 months

Products

  • pgAdmin 47
  • server1

2 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-17 of 17 CVEs
CVE-2026-7819
Analyzed
8.1
pgadmin.org Multiple Products

Symbolic-link path traversal (CWE-61, CWE-22) in pgAdmin 4 File Manager

2026-05-12
CVE-2026-7818
Analyzed
7
pgadmin.org Multiple Products

Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager

2026-05-12
CVE-2026-7816
Analyzed
8.8
pgadmin.org Multiple Products

OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export query export

2026-05-12
CVE-2026-7815
Analyzed
8.8
pgadmin.org server

SQL injection vulnerability in pgAdmin 4 Maintenance Tool

2026-05-12
CVE-2026-7813
Analyzed
9.9
pgadmin.org pgAdmin 4

An authorization flaw in pgAdmin 4 allows authenticated users to access private server data and execute arbitrary commands by manipulating object IDs...

2026-05-12
CVE-2026-17566
Analyzed
9.9
pgadmin.org pgAdmin 4

An OS command injection vulnerability in the Import/Export Data tool of pgAdmin 4 allows authenticated users to execute arbitrary commands on the unde...

2026-08-01
CVE-2026-17351
Analyzed
9
pgadmin.org pgAdmin 4

A flawed fix in pgAdmin 4 allows for SQL injection via AI Assistant tool calls, enabling attackers to execute arbitrary multi-statement SQL commands.

2026-08-01
CVE-2026-17349
Analyzed
9.6
pgadmin.org pgAdmin 4

A vulnerability in the pgAdmin 4 Workspaces feature allows authenticated users to clone and inherit sensitive database credentials from other users, l...

2026-08-01
CVE-2026-17347
Analyzed
7.5
pgadmin.org pgAdmin 4

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7

2026-08-01
CVE-2026-17346
Analyzed
8.8
pgadmin.org pgAdmin 4

The fix for CVE-2026-12044 in pgAdmin 4 9

2026-08-01
CVE-2026-1707
Analyzed
7.4
pgadmin.org Multiple Products

pgAdmin versions 9

2026-02-06
CVE-2026-12044
Analyzed
8.8
pgadmin.org pgAdmin 4

SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON

2026-06-19
CVE-2025-9636
Analyzed
7.9
pgadmin.org Multiple Products

pgAdmin <= 9

2025-09-04
CVE-2025-13780
Analyzed
9.1
pgadmin.org Multiple Products

pgAdmin versions up to 9.10 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restore...

2025-12-12
CVE-2025-12765
Analyzed
7.5
pgadmin.org Multiple Products

pgAdmin <= 9

2025-11-14
CVE-2025-12764
Analyzed
7.5
pgadmin.org Multiple Products

pgAdmin <= 9

2025-11-14
CVE-2025-12762
Analyzed
9.1
pgadmin.org Multiple Products

pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores...

2025-11-14