Pgadmin

Pgadmin 4

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 05.02.2026 17:30:05
  • Zuletzt bearbeitet 26.02.2026 22:20:45

pgAdmin versions 9.11 are affected by a Restore restriction bypass via key disclosure vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. An attacker with access to the pgAdmin web interface can...

  • EPSS 0.17%
  • Veröffentlicht 11.12.2025 18:30:47
  • Zuletzt bearbeitet 19.12.2025 19:51:13

pgAdmin versions up to 9.10 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. This issue allows attackers to inject and execute arbitrary commands...

  • EPSS 0.05%
  • Veröffentlicht 13.11.2025 13:15:45
  • Zuletzt bearbeitet 19.11.2025 21:18:09

pgAdmin <= 9.9  is affected by a vulnerability in the LDAP authentication mechanism allows bypassing TLS certificate verification.

  • EPSS 0.12%
  • Veröffentlicht 13.11.2025 13:15:44
  • Zuletzt bearbeitet 19.11.2025 21:19:33

pgAdmin <= 9.9  is affected by an LDAP injection vulnerability in the LDAP authentication flow that allows an attacker to inject special LDAP characters in the username, causing the DC/LDAP server and the client to process an unusual amount of data D...

  • EPSS 0.08%
  • Veröffentlicht 13.11.2025 13:15:44
  • Zuletzt bearbeitet 01.12.2025 20:15:49

pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused by the use of shell=True during backup and restore operations, enabling attackers to execute arbitrary system commands by providin...

  • EPSS 0.16%
  • Veröffentlicht 13.11.2025 13:15:44
  • Zuletzt bearbeitet 01.12.2025 20:15:49

pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. This issue allows attackers to inject and execute arbitrary commands ...

  • EPSS 0.02%
  • Veröffentlicht 04.09.2025 16:43:27
  • Zuletzt bearbeitet 11.09.2025 21:26:47

pgAdmin <= 9.7 is affected by a Cross-Origin Opener Policy (COOP) vulnerability. This vulnerability allows an attacker to manipulate the OAuth flow, potentially leading to unauthorised account access, account takeover, data breaches, and privilege e...

  • EPSS 0.13%
  • Veröffentlicht 03.04.2025 13:15:43
  • Zuletzt bearbeitet 23.04.2025 22:24:39

pgAdmin <= 9.1 is affected by a security vulnerability with Cross-Site Scripting(XSS). If attackers execute any arbitrary HTML/JavaScript in a user's browser through query result rendering, then HTML/JavaScript runs on the browser.

Exploit
  • EPSS 77.9%
  • Veröffentlicht 03.04.2025 13:15:43
  • Zuletzt bearbeitet 17.09.2025 18:04:10

Remote Code Execution security vulnerability in pgAdmin 4 (Query Tool and Cloud Deployment modules). The vulnerability is associated with the 2 POST endpoints; /sqleditor/query_tool/download, where the query_commited parameter and /cloud/deploy end...

  • EPSS 92.88%
  • Veröffentlicht 23.09.2024 17:15:14
  • Zuletzt bearbeitet 22.09.2025 18:37:17

pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.