References https://www.anquanke.com/post/id/313226 https://cloud.tencent.com/developer/article/2623496 https://www.cnblogs.com/hetianlab/p/19361839 https://nvd.nist.gov/vuln/detail/CVE-2025-13780 https://www.cnvd.org.cn/flaw/show/CNVD-2024-02178 https://cn-sec.com/archives/4799086.html https://blog.csdn.net/breeze915/article/details/147143402 https://www.sentinelone.com/vulnerability-database/cve-2025-2945/ https://github.com/abrewer251/CVE-2025-2945_PgAdmin_PoC https://nvd.nist.gov/vuln/detail/CVE-2025-2945 https://blog.certcube.com/pgadmin-4-9-1-authenticated-rce-cve-2025-2945/
Related VulnerabilitiesPoCCVE-2022-4223: pgAdmin < 6.17 - Unauthenticated Remote Code ExecutionPoCCVE-2007-5728: phpPgAdmin <=4.1.1 - Cross-Site ScriptingPoCCVE-2008-5587: phpPgAdmin <=4.2.1 - Local File InclusionPoCCVE-2024-9014: pgAdmin 4 - Authentication BypassPgAdmin4 /login 信息泄露漏洞 (CVE-2024-9014)pgAdmin4敏感信息泄露漏洞(CVE-2024-9014)phpPgAdmin /phppgadmin/redirect.php 默认口令漏洞pgAdmin4 OAuth2 client ID与secret敏感信息泄漏漏洞pgAdmin 4 存在身份验证缺陷漏洞PgAdmin pga4_session 目录遍历漏洞pgAdmin validate_binary_path 远程代码执行漏洞