CVE-2026-34725Disclosure

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists in DbGate because attacker-controlled SVG icon strings are rendered as raw HTML without sanitization. In the web UI this allows script execution in another user's browser; in the Electron desktop app this can escalate to local code execution because Electron is configured with nodeIntegration: true and contextIsolation: false. This issue has been patched in version 7.1.5.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 4 mentions (2026-04-03); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-04-03: 4Mentions · 2026-04-07: 1Patch / Workaround · 2026-04-07: 1Technical Details · 2026-04-03: 404-0304-07
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-034
Disclosure4
2026-04-071
Patch1
Full discourse5 posts
  • Firmis Labs@FirmisLabs
    Patch

    CVE-2026-34725 · NIST 8.2/10 https://nvd.nist.gov/vuln/detail/CVE-2026-34725 ask your AI: "check if my project or team uses DbGate and if it's below version 7.1.5" then: "update DbGate to version 7.1.5 or later and make sure database connections still work"

    Post summary

    The advisory recommends updating DbGate to version 7.1.5 or later to mitigate CVE-2026-34725.

    1000032
    1 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-34725 DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists in DbGate because attacker-controlled SVG ico… https://www.cve.org/CVERecord?id=CVE-2026-34725 ----- Traducción: CVE-2026-34725 DbG… http://infoflow.cloud`

    Post summary

    CVE-2026-34725 is a stored XSS flaw in DbGate versions 7.0.0 to before 7.1.5, disclosed via the CVE record with no active exploitation or patch mentioned.

    0000035
    65 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34725 DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists in DbGate because attacker-controlled SVG ico… https://www.cve.org/CVERecord?id=CVE-2026-34725

    Post summary

    CVE-2026-34725 is a stored cross‑site scripting flaw in DbGate versions 7.0.0 through 7.1.4 that can be triggered via attacker‑controlled SVG icons. The vulnerability has been formally recorded and disclosed.

    00000233
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-34725 - High DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists in DbGate because attacker-controlled SVG icon strings are rendered as... https://www.thehackerwire.com/vulnerability/CVE-2026-34725/ https://t.co/jyHCpOedDg

    Post summary

    The text announces a stored XSS vulnerability (CVE‑2026‑34725) in DbGate, providing technical details but no PoC, exploit code, patch, or evidence of active exploitation.

    0000034
    163 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-34725 - High DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists in DbGate because attacker-controlled SVG icon strings are rendered as... https://www.thehackerwire.com/vulnerability/CVE-2026-34725/ https://t.co/u7YiqyYnTr

    Post summary

    The post announces a stored XSS vulnerability (CVE‑2026‑34725) in DbGate for versions 7.0.0 up to 7.1.4, highlighting how attacker‑controlled SVG icons can be used, but provides no exploit details, patches, or evidence of active exploitation.

    0000050
    163 followersView on X

Explore more