Technology · PyPI
pgadmin4 (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 28 vulnerabilities in pgadmin4 (PyPI): 0 in the last 7 days and 20 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-1707, was published on 13 July 2026.
- Last 7 days
- 0
- Last 90 days
- 20
- Critical, all time
- 1
- Exploited in the wild
- 0
About pgadmin4 (PyPI)
An open-source administration and management tool for the PostgreSQL database.
Latest pgadmin4 (PyPI) vulnerabilities
- CVE-2026-1707: PYSEC-2026-2864 - pgadmin4 affected by a Restore restriction bypass via key disclosure vulnerabilitylowCVSS 3.1EPSS 0.4%
- CVE-2025-12765: PYSEC-2026-1773 - pgAdmin has vulnerability in LDAP authentication mechanism that allows bypassing TLS certificate…lowCVSS 3.1EPSS 0.2%
- CVE-2025-12764: PYSEC-2026-1772 - pgAdmin is affected by an LDAP injection vulnerabilitylowCVSS 3.1EPSS 0.4%
- CVE-2025-12763: PYSEC-2026-1776 - pgAdmin 4 has command injection vulnerability on Windows systemslowCVSS 3.1EPSS 0.9%
- CVE-2025-9636: PYSEC-2026-1769 - pgadmin4 is affected by a Cross-Origin Opener Policy (COOP) vulnerabilitylowCVSS 3.1EPSS 0.2%
- CVE-2023-1907: PYSEC-2026-1770 - pgAdmin has Incorrect Default PermissionslowCVSS 3.1EPSS 0.4%
- CVE-2024-9014: PYSEC-2026-1775 - OAuth2 client ID and secret exposed through the web browserlowCVSS 3.1EPSS 9.7%
- CVE-2024-4216: PYSEC-2026-1777 - pgAdmin Cross-site Scripting vulnerability in /settings/store API response json payloadlowCVSS 3.1EPSS 0.5%
- CVE-2024-4215: PYSEC-2026-1768 - pgAdmin is affected by a multi-factor authentication bypass vulnerabilitylowCVSS 3.1EPSS 0.6%
- CVE-2024-3116: PYSEC-2026-1767 - pgAdmin Remote Code Execution (RCE) vulnerabilitylowCVSS 3.1EPSS 65.6%
- CVE-2023-5002: PYSEC-2026-1774 - pgAdmin failed to properly control the server codelowCVSS 3.1EPSS 1.8%
- CVE-2023-0241: PYSEC-2026-1771 - pgAdmin 4 vulnerable to directory traversallowCVSS 3.1EPSS 8.8%
- CVE-2023-22298: PYSEC-2026-894 - pgAdmin 4 Open Redirect vulnerabilitylowCVSS 3.1EPSS 0.9%
- CVE-2022-4223: PYSEC-2026-893 - pgadmin4 vulnerable to Code InjectionlowCVSS 3.1EPSS 80.1%
- CVE-2022-0959: PYSEC-2026-729 - pgAdmin 4 Path Traversal vulnerabilitylowCVSS 3.1EPSS 1.0%
- CVE-2024-2044: PYSEC-2026-453 - pgAdmin 4 vulnerable to Unsafe Deserialization and Remote Code Execution by an Authenticated userlowCVSS 3.1EPSS 79.5%
- CVE-2025-13780: PYSEC-2026-450 - pgadmin4 has a Meta-Command Filter Command ExecutionlowCVSS 3.1EPSS 0.9%
- CVE-2025-12762: PYSEC-2026-454 - pgAdmin4 vulnerable to Remote Code Execution (RCE) when running in server modelowCVSS 3.1EPSS 12.7%
- CVE-2025-2946: PYSEC-2026-449 - pgAdmin 4 Vulnerable to Cross-Site Scripting (XSS) via Query Result RenderinglowCVSS 3.1EPSS 0.3%
- CVE-2025-2945: PYSEC-2026-451 - pgAdmin 4 Vulnerable to Remote Code ExecutionlowCVSS 3.1EPSS 56.3%
- CVE-2026-7820: PostgreSQL pgAdmin 4 account lockout bypass in login viewsmediumCVSS 6.5EPSS 0.3%
- CVE-2026-7819: PostgreSQL pgAdmin 4 symbolic-link path traversal in File ManagerhighCVSS 8.1EPSS 0.5%
- CVE-2026-7818: PostgreSQL pgAdmin 4 insecure deserialization in FileBackedSessionManagerhighCVSS 7EPSS 0.4%
- CVE-2026-7817: PostgreSQL pgAdmin 4 LFI and SSRF in LLM API endpointsmediumCVSS 6.5EPSS 0.4%
- CVE-2026-7816: PostgreSQL pgAdmin 4 OS command injection in Import/Export query exporthighCVSS 8.8EPSS 2.2%
Most severe pgadmin4 (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-7813: PostgreSQL pgAdmin 4 authorization bypass and RCE in server modecriticalCVSS 9.9EPSS 0.7%
- CVE-2026-7816: PostgreSQL pgAdmin 4 OS command injection in Import/Export query exporthighCVSS 8.8EPSS 2.2%
- CVE-2026-7815: PostgreSQL pgAdmin 4 SQL injection in Maintenance ToolhighCVSS 8.8EPSS 0.6%
- CVE-2026-7819: PostgreSQL pgAdmin 4 symbolic-link path traversal in File ManagerhighCVSS 8.1EPSS 0.5%
- CVE-2026-7818: PostgreSQL pgAdmin 4 insecure deserialization in FileBackedSessionManagerhighCVSS 7EPSS 0.4%
- CVE-2026-7817: PostgreSQL pgAdmin 4 LFI and SSRF in LLM API endpointsmediumCVSS 6.5EPSS 0.4%
- CVE-2026-7820: PostgreSQL pgAdmin 4 account lockout bypass in login viewsmediumCVSS 6.5EPSS 0.3%
- CVE-2026-7814: PostgreSQL pgAdmin 4 stored XSS in Browser Tree and Explain VisualizermediumCVSS 4.8EPSS 0.3%
- CVE-2022-4223: PYSEC-2026-893 - pgadmin4 vulnerable to Code InjectionlowCVSS 3.1EPSS 80.1%
- CVE-2024-2044: PYSEC-2026-453 - pgAdmin 4 vulnerable to Unsafe Deserialization and Remote Code Execution by an Authenticated userlowCVSS 3.1EPSS 79.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 6 | 0 | |
| 6 Jul 2026 | 13 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/pgadmin4.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "pgadmin4 (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/pgadmin4, 26 September 2026.