CVE-2026-17566
- EPSS 0.41%
- Veröffentlicht 31.07.2026 16:17:00
- Zuletzt bearbeitet 05.08.2026 20:00:10
pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wrappe...
CVE-2026-1707
- EPSS 0.39%
- Veröffentlicht 05.02.2026 17:30:05
- Zuletzt bearbeitet 26.02.2026 22:20:45
pgAdmin versions 9.11 are affected by a Restore restriction bypass via key disclosure vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. An attacker with access to the pgAdmin web interface can...
CVE-2025-13780
- EPSS 0.92%
- Veröffentlicht 11.12.2025 18:30:47
- Zuletzt bearbeitet 07.10.2026 20:10:01
pgAdmin versions up to 9.10 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. This issue allows attackers to inject and execute arbitrary commands...
CVE-2025-12765
- EPSS 0.19%
- Veröffentlicht 13.11.2025 13:15:45
- Zuletzt bearbeitet 07.10.2026 21:10:00
pgAdmin <= 9.9 is affected by a vulnerability in the LDAP authentication mechanism allows bypassing TLS certificate verification.
CVE-2025-12762
- EPSS 12.21%
- Veröffentlicht 13.11.2025 13:15:44
- Zuletzt bearbeitet 01.12.2025 20:15:49
pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. This issue allows attackers to inject and execute arbitrary commands ...
CVE-2025-12764
- EPSS 0.39%
- Veröffentlicht 13.11.2025 13:15:44
- Zuletzt bearbeitet 07.10.2026 21:10:00
pgAdmin <= 9.9 is affected by an LDAP injection vulnerability in the LDAP authentication flow that allows an attacker to inject special LDAP characters in the username, causing the DC/LDAP server and the client to process an unusual amount of data D...
CVE-2025-2946
- EPSS 0.31%
- Veröffentlicht 03.04.2025 13:15:43
- Zuletzt bearbeitet 23.04.2025 22:24:39
pgAdmin <= 9.1 is affected by a security vulnerability with Cross-Site Scripting(XSS). If attackers execute any arbitrary HTML/JavaScript in a user's browser through query result rendering, then HTML/JavaScript runs on the browser.
CVE-2023-1907
- EPSS 0.45%
- Veröffentlicht 09.01.2025 08:15:24
- Zuletzt bearbeitet 20.06.2025 17:57:08
A vulnerability was found in pgadmin. Users logging into pgAdmin running in server mode using LDAP authentication may be attached to another user's session if multiple connection attempts occur simultaneously.
CVE-2024-4215
- EPSS 0.63%
- Veröffentlicht 02.05.2024 18:15:07
- Zuletzt bearbeitet 19.09.2025 13:37:32
pgAdmin <= 8.5 is affected by a multi-factor authentication bypass vulnerability. This vulnerability allows an attacker with knowledge of a legitimate account’s username and password may authenticate to the application and perform sensitive actions w...
CVE-2024-4216
- EPSS 0.46%
- Veröffentlicht 02.05.2024 18:15:07
- Zuletzt bearbeitet 19.09.2025 13:27:28
pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end.