Back to Database
Status published
High
CVE-2024-4216
XSS vulnerability in /settings/store API response json payload in pgAdmin 4
Vulnerability Description
pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-4216
Credits & Attribution
No credits recorded in the NVD database.
References
More from pgadmin.org
View All →CVE-2025-9636
Cross-Origin Opener Policy Vulnerability in pgAdmin 4
High
7.9
CVE-2025-2946
Cross-Site Vulnerability(XSS) due to arbitrary HTML/JavaScript gets executed while query result rendering in Query Tool and View/Edit Data Tool of pgAdmin 4
Critical
9.1
CVE-2025-2945
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
Critical
9.9
CVE-2025-13780
Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)
Critical
9.1
CVE-2025-12765
pgAdmin 4: LDAP authentication flow vulnerable to TLS certificate verification bypass.
High
7.5
Affected Vendor
pgadmin.org
View all reports →Affected Software
pgAdmin 4
Vulnerable Versions:
0
Timeline
Official Publish:
May 2nd, 2024
Last Modified:
February 13th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.