In the pgpartman (aka PG Partition Manager) extension before 4.5.1 for PostgreSQL, arbitrary code execution can be achieved via SECURITY DEFINER functions because an explicit searchpath is not set.
{ "binaries": [ { "binary_version": "2.2.2-2", "binary_name": "postgresql-9.5-partman" } ] }
{ "binaries": [ { "binary_version": "3.1.2-1", "binary_name": "postgresql-10-partman" } ] }
{ "binaries": [ { "binary_version": "4.3.0-1", "binary_name": "postgresql-12-partman" } ] }
{ "binaries": [ { "binary_version": "4.6.0-1", "binary_name": "postgresql-14-partman" } ] }