Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

PostgreSQL Anonymizer — Vulnerabilities & Security Advisories 11

All 11 CVE vulnerabilities found in PostgreSQL Anonymizer, with AI-generated Chinese analysis, references, and POCs.

Vendor: DALIBO

CVE ID Title CVSS Severity Published
CVE-2026-83534 PostgreSQL Anonymizer: Privilege escalation to superuser via anon.anonymize_database_parallel() CWE-250 6.4 Medium 2026-09-06
CVE-2026-19634 PostgreSQL Anonymizer: SQL injection in import_database_rules() and import_roles_rules() via crafted object names / JSON CWE-89 6.4 Medium 2026-09-06
CVE-2026-19633 PostgreSQL Anonymizer: unprivileged masked users can execute code via operators, domain casts and view subqueries CWE-89 8.8 High 2026-09-06
CVE-2026-13455 PostgreSQL Anonymizer: Unrestricted function can leak the secret salt CWE-328 4.3 Medium 2026-06-30
CVE-2026-11945 PostgreSQL Anonymizer: SQL injection in the rules import functions CWE-89 6.4 Medium 2026-06-11
CVE-2026-9617 PostgreSQL Anonymizer: malicious column name allows SQL injection via anon.k_anonymity() function CWE-89 6.8 Medium 2026-05-27
CVE-2026-2361 Improper search_path protection in PostgreSQL Anonymizer 2.5 allows any user with create privilege to gain superuser privileges CWE-427 8.0 High 2026-02-11
CVE-2026-2360 Improper search_path protection in PostgreSQL Anonymizer 2.5 allows any user to gain superuser privileges in PostgreSQL 14 CWE-427 8.0 High 2026-02-11
CVE-2025-5690 Cursor allows PostgreSQL Anonymizer masked user to gain unauthorized access to authentic data CWE-200 6.5 Medium 2025-06-04
CVE-2024-2339 Improper Input Validation in PostgreSQL Anonymizer 1.2 allows table owner to gain superuser privileges via masking rule CWE-20 8.0 High 2024-03-08
CVE-2024-2338 SQL Injection in PostgreSQL Anonymizer 1.2 allows table owner to gain superuser privileges via masking rule CWE-89 8.0 High 2024-03-08

All 11 known CVE vulnerabilities affecting PostgreSQL Anonymizer with full Chinese analysis, references, and POCs where available.