Pgadmin 4
Vendor:
First CVE: Mar 16, 2022 · Active for 4 years
35
Total CVEs
More Total CVEs than 96% of tracked products
7.0
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 61% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Pgadmin 4 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 16, 2022
4 years ago
Most Recent CVE
Jun 19, 2026
35 days ago
CVE Severity & Scoring
Pgadmin 435 CVEs
40%
46%
14%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (2.9%)
Network34 (97.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low32 (91.4%)
High3 (8.6%)
Unknown0 (0.0%)
User Interaction
None25 (71.4%)
Unknown0 (0.0%)
Required10 (28.6%)
Privileges Required
Low22 (62.9%)
High1 (2.9%)
None12 (34.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (35 CVEs).
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-2044CRITICAL pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is running on Windows, an unauthenticat | Mar 7, 2024 | 9.9 | 82 | NO | YES |
CVE-2022-4223HIGH The pgAdmin server includes an HTTP API that is intended to be used to validate the path a user selects to external PostgreSQL utilities such as pg_dump and pg_restore. The utility | Dec 13, 2022 | 8.8 | 81 | NO | YES |
CVE-2024-3116CRITICAL pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on th | Apr 4, 2024 | 9.8 | 78 | NO | YES |
CVE-2025-2945HIGH Remote Code Execution security vulnerability in pgAdmin 4 (Query Tool and Cloud Deployment modules).
The vulnerability is associated with the 2 POST endpoints; /sqleditor/query_t | Apr 3, 2025 | 8.8 | 67 | NO | YES |
CVE-2025-12762CRITICAL pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. | Nov 13, 2025 | 9.8 | 41 | NO | NO |
CVE-2026-12046CRITICAL Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/update_connection/<sgid>/<sid>/<did> | Jun 19, 2026 | 9.0 | 39 | NO | NO |
CVE-2026-12045HIGH Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with the privileg | Jun 19, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-7813CRITICAL Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules.
Multiple endpoints fetched user- | May 11, 2026 | 9.9 | 38 | NO | NO |
CVE-2026-12044HIGH SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<description>'`` for a user-supplied description field. The Jinja templates for Domains (a | Jun 19, 2026 | 8.8 | 37 | NO | NO |
CVE-2024-9014MEDIUM pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, | Sep 23, 2024 | 6.5 | 37 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (35 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
8.6% of CVEs· 97th percentile
Nuclei
2 CVEs
5.7% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (35 CVEs).
Media Mentions
Signals from CVEs in this product scope (35 CVEs).
Top CNAs Publishing CVEs For Pgadmin 4
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.11 | 1 | 6.3 | 0.4% | 0 | 0 |