VYPR

Pgadmin4

by Pgadmin.org

pypi: pgadmin4

Source repositories

CVEs (48)

  • CVE-2017-20052MedJun 16, 2022
    risk 0.33cvss 5.0epss 0.01

    A vulnerability classified as problematic was found in Python 2.7.13. This vulnerability affects unknown code of the component pgAdmin4. The manipulation leads to uncontrolled search path. The attack can be initiated remotely. The exploit has been disclosed to the public and may…

  • CVE-2023-5002MedSep 22, 2023
    risk 0.32cvss 6.0epss 0.01

    A flaw was found in pgAdmin. This issue occurs when the pgAdmin server HTTP API validates the path a user selects to external PostgreSQL utilities such as pg_dump and pg_restore. Versions of pgAdmin prior to 7.6 failed to properly control the server code executed on this API,…

  • CVE-2026-86861MedSep 17, 2026
    risk 0.31cvss 5.9epss 0.00

    pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with Filemanager.check_access_permission() and then opened the file for writing with a plain open() call. CVE-2026-7819 had previously hardened the separate…

  • CVE-2026-17350MedJul 31, 2026
    risk 0.28cvss 5.4epss 0.00

    The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce its permission check consistently. In SERVER mode, pgAdmin 4 gates each tool behind a per-tool Flask-Security permission, but the permission decorator…

  • CVE-2026-7814MedMay 11, 2026
    risk 0.24cvss 4.8epss 0.00

    Stored cross-site scripting (XSS) vulnerability in pgAdmin 4 Browser Tree and Explain Visualizer modules. User-controlled PostgreSQL object names (database, schema, table, column, etc.) were assigned to DOM elements via innerHTML, allowing crafted object names containing HTML…

  • CVE-2026-12050MedJun 19, 2026
    risk 0.21cvss 4.3epss 0.00

    SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/{sid}). The user-supplied 'value' field was interpolated directly into the SQL string with str.format() instead of being passed as a bound parameter, allowing an authenticated…

  • CVE-2026-12049MedJun 19, 2026
    risk 0.21cvss 4.3epss 0.00

    Open redirect in pgAdmin 4's multi-factor authentication flow. The MFA validate and register endpoints honoured the user-supplied 'next' query/form parameter without confirming the target pointed back inside pgAdmin, so an authenticated victim who clicked…

  • CVE-2026-12047LowJun 19, 2026
    risk 0.16cvss 3.5epss 0.00

    HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoints under /rds/, /azure/, /google/, and the top-level /cloud/ blueprint propagated AWS / Azure / Google SDK exception text — and the related file-resolution…

Page 3 of 3