pkg:PyPI/pgadmin4
28 total CVEsCRITICAL6HIGH14MEDIUM8
✅ Check your installed version
All known vulnerabilities
- CRITICAL9.9CVE-2026-7813pgAdmin 4 server mode has an authorization vulnerability affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modulesfrom 0, < 9.15
- from 0, < 9.2
- CRITICAL9.9CVE-2024-2044pgAdmin 4 vulnerable to Unsafe Deserialization and Remote Code Execution by an Authenticated userfrom 0, < 8.4
- from 0, < 9.11
- CRITICAL9.1CVE-2025-12762pgAdmin4 vulnerable to Remote Code Execution (RCE) when running in server modefrom 0, < 9.10
- CRITICAL9.1CVE-2025-2946pgAdmin 4 Vulnerable to Cross-Site Scripting (XSS) via Query Result Renderingfrom 0, < 9.2
- from 0, < 9.15
- from 0, < 9.15
- from 0, < 6.17
- from 0, < 8.12
- from 0, < 9.15
- from 0, < 7.0
- from 0, < 9.8
- from 0, < 9.10
- HIGH7.5CVE-2025-12765pgAdmin has vulnerability in LDAP authentication mechanism that allows bypassing TLS certificate verificationfrom 0, < 9.10
- HIGH7.4CVE-2026-1707pgadmin4 affected by a Restore restriction bypass via key disclosure vulnerabilityfrom 0, < 9.12
- HIGH7.4CVE-2024-4216pgAdmin Cross-site Scripting vulnerability in /settings/store API response json payloadfrom 0, < 8.6
- from 0, < 8.6
- from 0, < 8.5
- from 0, < 9.15
- from 0, < 9.10
- MEDIUM6.5CVE-2026-7817pgAdmin 4 contains local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilitiesfrom 0, < 9.15
- from 0, < 9.15
- from 0, < 6.19
- from 0, < 6.7
- from 0, < 6.14
- from 0, < 7.7
- MEDIUM4.8CVE-2026-7814pgAdmin 4: Stored cross-site scripting (XSS) vulnerability in Browser Tree and Explain Visualizer modulesfrom 0, < 9.15