Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cyberpanel CRITICAL 9.1
CVE-2026-41473

CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated …

Fix: 2.4.4+
Fix from $2,300 2026-04-24
Cyberpanel MEDIUM 6.1
CVE-2026-41472

CyberPanel versions prior to 2.4.5 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/cal…

Fix: 2.4.4+
Fix from $1,600 2026-04-24
Cyberpanel MEDIUM 6.1
CVE-2024-56112

CyberPanel (aka Cyber Panel) before f0cf648 allows XSS via token or username to plogical/phpmyadminsignin.php.

Fix: 2024-11-11+
Fix from $1,600 2024-12-16
Cyberpanel HIGH 8.8
CVE-2024-53376EPSS 11%

CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the web…

Fix: 2.3.8+
Fix from $1,950 2024-12-16
Cyberpanel MEDIUM 6.5
CVE-2024-54679

CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.

Fix: after 2.3.7
Fix from $1,600 2024-12-05
Cyberpanel CRITICAL 9.8
CVE-2024-51378 KEVEPSS 95%

getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and e…

Fix: 2.3.8+
Fix from $2,300 2024-10-29
Cyberpanel CRITICAL 9.8
CVE-2024-51567 KEVEPSS 87%

upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute …

Fix: 2.3.8+
Fix from $2,300 2024-10-29
Cyberpanel CRITICAL 9.8
CVE-2024-51568EPSS 45%

CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filem…

Fix: 2.3.5+
Fix from $2,300 2024-10-29
Cyberpanel HIGH 8.8
CVE-2019-13056

An issue was discovered in CyberPanel through 1.8.4. On the user edit page, an attacker can edit the administrator's e-mail and password because of t…

Fix: after 1.8.4
Fix from $1,950 2019-07-02