-
Latest Version
-
Operating System
Windows 10 (64-bit) / Windows 11
-
User Rating
Click to vote -
Author / Product
-
Filename
pgadmin4-9.15-x64.exe
Sometimes latest versions of the software can cause issues when installed on older devices or devices running an older version of the operating system.
Software makers usually fix these issues but it can take them some time. What you can do in the meantime is to download and install an older version of pgAdmin 4 9.15.
For those interested in downloading the most recent release of pgAdmin or reading our review, simply click here.
All old versions distributed on our website are completely virus-free and available for download at no cost.
We would love to hear from you
If you have any questions or ideas that you want to share with us - head over to our Contact page and let us know. We value your feedback!
What's new in this version:
Supported Database Servers:
- PostgreSQL: 13, 14, 15, 16, 17 and 18
- EDB Advanced Server: 13, 14, 15, 16, 17 and 18
- Bundled PostgreSQL Utilities:
- psql, pg_dump, pg_dumpall, pg_restore: 18.2
- New features:
- Allow the container image to run as a non-default user via the PUID and PGID environment variables
Housekeeping:
- Update the Swedish translation
- Bump Python and JavaScript dependencies
- Fix the Czech translation for ‘Refresh’
- Bump runtime dependencies and upgrade ESLint to v10
- Update the Russian translation
- Bump runtime and development dependencies
- Use an <OWNER> placeholder in resql tests instead of a hardcoded ‘postgres’ role to support non-default superuser names
- Update the Spanish translation
- Update the Italian translation
Fixed:
- Use absolute paths for a2enmod and a2enconf in the Debian setup script so it works when /usr/sbin is not on PATH
- Fix cross-user data access and shared-server privilege escalation in server mode. Also applies the @with_object_filters access-control decorator to ServerNode.list.
- Tighten Shared Server feature parity, owner-only field handling, and write guards as a follow-up to the data-isolation hardening
- Fix stored cross-site scripting (XSS) via crafted PostgreSQL object names rendered in the Browser Tree and Explain Visualizer
- Fix SQL injection in Maintenance tool option values
- Fix OS command injection in Import/Export query export
- Fix local-file inclusion and server-side request forgery in LLM API configuration endpoints
- Fix unsafe deserialization in the session manager that could lead to remote code execution. Also encrypts session files at rest using Fernet, restricts session-file permissions to 0o600, switches the session-digest default from SHA-1 to SHA-256, drops several non-roundtrippable live objects from the session (AuthSourceManager and the Azure, RDS, Google Cloud, and BigAnimal cloud-provider instances), tightens DATA_DIR file and directory permissions at creation, creates pgadmin4.log with mode 0o600, hardens EnhancedRotatingFileHandler._open against rotation failures, and bounds the user_info_server prompt retry loop so a non-interactive caller cannot spin forever
- Fix symlink-based path traversal in the file manager
- Fix account-lockout bypass on Flask-Security’s default /login view by overriding User.is_active and User.is_locked() so the locked field is honored on every authentication path
Additional changes (no associated issue):
- The commits below did not have a dedicated GitHub issue. They are listed here for transparency.
Fixed:
- Restore the SERVER_MODE python-test path and fix two endpoint regressions surfaced by it
- Harden validation, preference, and connection-params paths against pre-existing edge cases
Test-suite stability:
- Harden click_modal backdrop wait and open_query_tool stale-element retry in feature tests
- Feature tests use sys.executable; sync yarn.lock to package.json
- PSQL socket tests use the authenticated tester; the role-dependencies test skips cleanly on auth failure
- Harden six regression tests against environmental drift
- Quote the username in the views/mview test helper for dotted local roles
- Quote the username in the types/compound-triggers test helpers for dotted local roles
- Quote the username in the user-mappings test helper for dotted local roles
- ImportExportServersTestCase uses sys.executable instead of a bare python and surfaces subprocess errors instead of swallowing them as a misleading JSON-parse failure
- Refactoring¶
- Factor the WTForms-error-to-JSON conversion into a helper and drop a dead import
Documentation:
- 9923eefca - Clarify in login.rst and ldap.rst that MAX_LOGIN_ATTEMPTS applies only to the INTERNAL authentication source. Operators using LDAP, OAuth2, Kerberos, or Webserver auth should rely on the upstream identity provider’s lockout policy and reverse-proxy request rate-limiting.
Dependencies:
- Non-breaking dependabot updates aggregated for v9.15
Python:
- boto3 1.42 -> 1.43 (python_version > '3.9'; Python 3.9 stays on 1.42)
- cryptography 46.0 -> 47.0
- psycopg 3.3.3 -> 3.3.4 (python_version >= '3.10')
- pycodestyle >=2.5.0 -> >=2.14.0
- requests >=2.21.0 -> >=2.33.1
- safety >=1.9.0 -> >=3.7.0
- testtools 2.8.7 -> 2.9.1
- typer 0.24 -> 0.25 (python > '3.9')
- JavaScript (web/):
- @tanstack/react-query 5.90 -> 5.100.5
- axios 1.15.2 -> 1.16.0
- moment-timezone 0.6.0 -> 0.6.2
- postcss 8.5.6 -> 8.5.12
- JavaScript (runtime/):
- axios 1.15.2 -> 1.16.0
- electron 41.3.0 -> 41.5.0
- eslint 10.2.1 -> 10.3.0
- globals 17.5.0 -> 17.6.0
OperaOpera 134.0 Build 5954.26 (64-bit)
BlueStacksBlueStacks 10.42.251.1002
PhotoshopAdobe Photoshop CC 2026 27.7 (64-bit)
WPS OfficeWPS Office Free 12.2.0.23196
GTA 6GTA 6 for PS5
CapCutCapCut Desktop 9.1.0
PC RepairPC Repair Tool 2026
Hero WarsHero Wars - Online Action Game
TradingViewTradingView - Trusted by 100 Million Traders
Halo: CampaignHalo: Campaign Evolved





Comments and User Reviews