{"id":"CVE-2026-7814","summary":"pgAdmin 4: Stored XSS via crafted PostgreSQL object names in Browser Tree and Explain Visualizer","details":"Stored cross-site scripting (XSS) vulnerability in pgAdmin 4 Browser Tree and Explain Visualizer modules.\n\nUser-controlled PostgreSQL object names (database, schema, table, column, etc.) were assigned to DOM elements via innerHTML, allowing crafted object names containing HTML markup to execute attacker-supplied JavaScript in the browser of any pgAdmin user who navigated to or executed EXPLAIN over the malicious object.\n\nFix replaces innerHTML with textContent.\n\nThis issue affects pgAdmin 4: before 9.15.","aliases":["GHSA-6p2c-69cv-3fxq","PYSEC-2026-2866"],"modified":"2026-07-15T01:49:08.359200405Z","published":"2026-05-11T14:35:49.411Z","related":["CGA-6m9h-q7pj-66qh"],"database_specific":{"cna_assigner":"PostgreSQL","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/7xxx/CVE-2026-7814.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/7xxx/CVE-2026-7814.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-7814"},{"type":"FIX","url":"https://github.com/pgadmin-org/pgadmin4/pull/9865"},{"type":"PACKAGE","url":"https://github.com/pgadmin-org/pgadmin4"},{"type":"EVIDENCE","url":"https://github.com/pgadmin-org/pgadmin4/issues/9865"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pgadmin-org/pgadmin4","events":[{"introduced":"31be1ae02619ebd11402af2a3f53b62c8d0cafd3"},{"fixed":"86a8b165abbefd62e78fd43edcd66c0d09649442"}],"database_specific":{"source":["AFFECTED_FIELD","CPE_RANGE"],"cpe":"cpe:2.3:a:pgadmin:pgadmin_4:*:*:*:*:*:postgresql:*:*","extracted_events":[{"introduced":"6.9"},{"fixed":"9.15"}]}}],"versions":["REL-9_14","REL-9_13","REL-9_12","REL-9_11","REL-9_10","REL-9_9","REL-9_8","REL-9_7","REL-9_6","REL-9_5","REL-9_4","REL-9_3","REL-9_2","REL-9_1","REL-9_0","REL-8_14","REL-8_13","REL-8_12","REL-8_11","REL-8_10","REL-8_9","REL-8_8","REL-8_7","REL-8_6","REL-8_5","REL-8_4","REL-8_3","REL-8_2","REL-8_1","REL-8_0","REL-7_8","REL-7_7","REL-7_6","REL-7_5","REL-7_4","REL-7_3","REL-7_2","REL-7_1","REL-7_0","REL-6_21","REL-6_20","REL-6_19","REL-6_18","REL-6_17","REL-6_16","REL-6_15","REL-6_14","REL-6_13","REL-6_12","REL-6_11","REL-6_10","REL-6_9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-7814.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"}]}