VYPR

Coolercontrold

Sign in to watch

by Coolercontrol

CVEs (4)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2026-5208Hig0.538.20.00Apr 8, 2026Command injection in alerts in CoolerControl/coolercontrold <4.0.0 allows authenticated attackers to execute arbitrary code as root via injected bash commands in alert names
CVE-2026-5301Hig0.497.60.00Apr 8, 2026Stored XSS in log viewer in CoolerControl/coolercontrol-ui <4.0.0 allows unauthenticated attackers to take over the service via malicious JavaScript in poisoned log entries
CVE-2026-5302Med0.416.30.00Apr 8, 2026CORS misconfiguration in CoolerControl/coolercontrold <4.0.0 allows unauthenticated remote attackers to read data and send commands to the service via malicious websites
CVE-2026-5300Med0.385.90.00Apr 8, 2026Unauthenticated functionality in CoolerControl/coolercontrold <4.0.0 allows unauthenticated attackers to view and modify potentially sensitive data via HTTP requests