216.73.216.197

CVE-2026-7814

· Published 11/05/2026 16:17 · Modified 11/05/2026 18:16

Labels: CVE-2026-7814 2026-05-11CVE-2026-7814CWE-79f86ef6dc-4d3a-42ad-8f28-e6d5547a5007

Essential information

Published
11/05/2026 16:17
Modified
11/05/2026 18:16
Author
Creator
CVSS
4.8 MEDIUM (v3) 4.8 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Stored cross-site scripting (XSS) vulnerability in pgAdmin 4 Browser Tree and Explain Visualizer modules. User-controlled PostgreSQL object names (database, schema, table, column, etc.) were assigned to DOM elements via innerHTML, allowing crafted object names containing HTML markup to execute attacker-supplied JavaScript in the browser of any pgAdmin user who navigated to or executed EXPLAIN over the malicious object. Fix replaces innerHTML with textContent. This issue affects pgAdmin 4: before 9.15.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
NVD
View on NVD

Affected products (CPE)

ProductCPE
pgadmin / pgadmin cpe:2.3:a:pgadmin:pgadmin:<9.15:*:*:*:*:*:*

References