VYPR

OpenPanel

by OpenPanel

Source repositories

CVEs (11)

  • CVE-2024-53584CriJan 31, 2025
    risk 0.67cvss 9.8epss 0.04

    OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.

  • CVE-2024-53537CriJan 31, 2025
    risk 0.62cvss 9.1epss 0.02

    An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager.

  • CVE-2026-85610HigSep 4, 2026
    risk 0.57cvss 8.8epss 0.01

    OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project members with read access to execute arbitrary code by recovering the native JavaScript Function constructor through mathjs matrix objects. Attackers can use the recovered…

  • CVE-2026-85614HigSep 4, 2026
    risk 0.56cvss 8.6epss 0.00

    OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker endpoint that accepts a fully client-controlled URL parameter with no private IP filtering or DNS-rebinding protection. Attackers can make the OpenPanel…

  • CVE-2026-85613HigSep 4, 2026
    risk 0.53cvss 8.2epss 0.00

    OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote attackers to execute scripts by supplying an SVG file URL. Attackers can host malicious SVG files with embedded scripts that…

  • CVE-2025-25871HigMar 14, 2025
    risk 0.52cvss 8.0epss 0.00

    An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function

  • CVE-2024-53582HigJan 31, 2025
    risk 0.52cvss 7.5epss 0.03

    An issue found in the Copy and View functions in the File Manager component of OpenPanel v0.3.4 allows attackers to execute a directory traversal via a crafted HTTP request.

  • CVE-2026-85612HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints that accept an attacker-supplied url parameter with insufficient validation. Attackers can force the API to fetch arbitrary internal hosts and…

  • CVE-2026-85609HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.01

    Openpanel before 2.3.0 contains an unauthenticated full-read server-side request forgery (SSRF) vulnerability in the GET /tools/site-checker endpoint (apps/api/src/controllers/tools.controller.ts). The endpoint passes a user-supplied url query parameter to fetchWithRedirects()…

  • CVE-2026-85611MedSep 4, 2026
    risk 0.42cvss 6.4epss 0.00

    OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to scope dashboard queries to the caller's project. Authenticated attackers can supply their own projectId…

  • CVE-2025-25872MedMar 14, 2025
    risk 0.36cvss 5.5epss 0.00

    An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function