VYPR

Cyberpanel

by Cyberpanel

Source repositories

CVEs (10)

  • CVE-2021-47949HigMay 10, 2026
    risk 0.57cvss 8.8epss 0.01

    CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files and execute remote code by exploiting symlink attacks through the filemanager controller endpoint. Attackers can manipulate the completeStartingPath parameter in…

  • CVE-2026-41473CriApr 24, 2026
    risk 0.52cvss 9.1epss 0.01

    CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/status-webhook and…

  • CVE-2026-41472MedApr 24, 2026
    risk 0.33cvss 6.1epss 0.01

    CyberPanel versions prior to 2.4.4 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/callback endpoint lacks authentication and allows unauthenticated attackers to inject malicious JavaScript by overwriting the…

  • CVE-2024-51378KEVOct 29, 2024
    risk 0.29cvss epss 0.95

    getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secMiddleware (which is only for a POST…

  • CVE-2024-51567KEVOct 29, 2024
    risk 0.28cvss epss 0.87

    upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which is only for a POST request) and using shell…

  • CVE-2024-51568Oct 29, 2024
    risk 0.10cvss epss 0.46

    CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell metacharacters.

  • CVE-2024-53376Dec 16, 2024
    risk 0.07cvss epss 0.11

    CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the websites/submitWebsiteCreation URI.

  • CVE-2024-56112Dec 16, 2024
    risk 0.00cvss epss 0.00

    CyberPanel (aka Cyber Panel) before f0cf648 allows XSS via token or username to plogical/phpmyadminsignin.php.

  • CVE-2024-54679Dec 5, 2024
    risk 0.00cvss epss 0.01

    CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.

  • CVE-2019-13056Jul 2, 2019
    risk 0.00cvss epss 0.01

    An issue was discovered in CyberPanel through 1.8.4. On the user edit page, an attacker can edit the administrator's e-mail and password because of the lack of CSRF protection.