mediumCVSS 4.8Vulnerability

CVE-2026-7814

Stored cross-site scripting (XSS) vulnerability in pgAdmin 4 Browser Tree and Explain Visualizer modules. User-controlled PostgreSQL object names (database, schema, table, column, etc.) were assigned to DOM elements via innerHTML, allowing crafted object names containing HTML markup to execute attacker-supplied JavaScript in the browser of any pgAdmin user who navigated to or executed EXPLAIN over the malicious object. Fix replaces innerHTML with textContent. This issue affects pgAdmin 4: before 9.15.

Properties

severity
medium
summary
pgAdmin 4: Stored cross-site scripting (XSS) vulnerability in Browser Tree and Explain Visualizer modules
epss_score
0.00163
cvss_score
4.8
ghsa_published
2026-05-11T18:31:44Z
source_url
https://github.com/advisories/GHSA-6p2c-69cv-3fxq
ghsa_updated
2026-05-18T14:32:33Z
ghsa_id
GHSA-6p2c-69cv-3fxq
cve_id
CVE-2026-7814
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
is_ghsa_only
false
epss_percentile
0.05983

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]pip/pgadmin4

AFFECTS (1)

[Software]pip/pgadmin4

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-7814 (CVSS 4.8) — Ninja Signal Threat Intelligence | Ninja Signal