Pghero is a performance-monitoring tool for PostgreSQL databases that provides a focused attack surface centered on a single product. Observed vulnerabilities recur around cross-site request forgery and error-message information disclosure, reflecting the web-interface and diagnostic-output character of a database administration panel.
The number and severity of CVEs published that impact products developed by Pghero Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-22626HIGH PgHero before 3.1.0 allows Information Disclosure via EXPLAIN because query results may be present in an error message. (Depending on database user privileges, this may only be inf | Jan 5, 2023 | 7.5 | 24 | NO | NO |
CVE-2020-16253HIGH The PgHero gem through 2.6.0 for Ruby allows CSRF. | Aug 5, 2020 | 8.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pghero Project.
Media articles that mention a CVE ID that affects a product developed by Pghero Project — matched by CVE ID, not by vendor name.