Cockpit
by Agentejo
Source repositories
CVEs (42)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-31891 | Hig | 0.43 | 7.7 | 0.00 | Mar 18, 2026 | Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API access enabled is potentially affected by a a SQL Injection vulnerability in the MongoLite Aggregation Optimizer. Any deployment where the… | ||
| CVE-2020-35850 | Med | 0.42 | 6.5 | 0.02 | Dec 30, 2020 | An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product. NOTE: the vendor states "I don't think [it] is a big real-life issue. | ||
| CVE-2023-41564 | Med | 0.40 | 6.1 | 0.01 | Sep 8, 2023 | An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a crafted .shtml file. | ||
| CVE-2020-14408 | Med | 0.40 | 6.1 | 0.03 | Jun 17, 2020 | An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login route allows for injection of arbitrary JavaScript code into a web page's content, creating a Reflected XSS attack vector. | ||
| CVE-2018-15538 | Med | 0.40 | 6.1 | 0.01 | Oct 15, 2018 | Agentejo Cockpit has multiple Cross-Site Scripting vulnerabilities. | ||
| CVE-2024-2001 | Med | 0.36 | 5.5 | 0.00 | Feb 29, 2024 | A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infected PDF file and store a malicious JavaScript payload to be executed when the file is uploaded. | ||
| CVE-2018-11471 | Med | 0.35 | 5.4 | 0.01 | May 25, 2018 | Cockpit 0.5.5 has XSS via a collection, form, or region. | ||
| CVE-2023-4451 | Med | 0.33 | 6.1 | 0.02 | Aug 20, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4. | ||
| CVE-2023-4432 | Med | 0.33 | 6.1 | 0.01 | Aug 19, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4. | ||
| CVE-2023-4321 | Med | 0.33 | 6.1 | 0.01 | Aug 14, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.4.3. | ||
| CVE-2023-1160 | Med | 0.29 | 5.5 | 0.00 | Mar 3, 2023 | Use of Platform-Dependent Third Party Components in GitHub repository cockpit-hq/cockpit prior to 2.4.0. | ||
| CVE-2023-4433 | Med | 0.28 | 5.4 | 0.00 | Aug 19, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4. | ||
| CVE-2023-4395 | Med | 0.28 | 5.4 | 0.01 | Aug 17, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4. | ||
| CVE-2023-4196 | Med | 0.28 | 5.4 | 0.00 | Aug 6, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3. | ||
| CVE-2023-0780 | Med | 0.28 | 5.4 | 0.00 | Feb 11, 2023 | Improper Restriction of Rendered UI Layers or Frames in GitHub repository cockpit-hq/cockpit prior to 2.3.9-dev. | ||
| CVE-2023-4422 | Med | 0.24 | 4.8 | 0.01 | Aug 18, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3. | ||
| CVE-2024-6126 | Low | 0.21 | 3.2 | 0.00 | Jul 3, 2024 | A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pam_env's user_readenv option, which leads to a denial of service (DoS) attack. | ||
| CVE-2025-7053 | Low | 0.16 | 3.5 | 0.00 | Jul 4, 2025 | A vulnerability was found in Cockpit up to 2.11.3. It has been rated as problematic. This issue affects some unknown processing of the file /system/users/save. The manipulation of the argument name/email leads to cross site scripting. The attack may be initiated remotely.… | ||
| CVE-2026-13533 | Med | 0.00 | 5.3 | 0.00 | Jun 29, 2026 | A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2. Affected by this issue is the function Spyc::YAMLLoad of the file /config/config.yaml of the component htaccess Handler. Such manipulation leads to files or directories accessible. It is possible to… | ||
| CVE-2021-32857 | Med | 0.00 | 6.1 | 0.01 | Feb 21, 2023 | Cockpit is a content management system that allows addition of content management functionality to any site. In versions 0.12.2 and prior, bad HTML sanitization in `htmleditor.js` may lead to cross-site scripting (XSS) issues. There are no known patches for this issue. |
- risk 0.43cvss 7.7epss 0.00
Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API access enabled is potentially affected by a a SQL Injection vulnerability in the MongoLite Aggregation Optimizer. Any deployment where the…
- risk 0.42cvss 6.5epss 0.02
An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product. NOTE: the vendor states "I don't think [it] is a big real-life issue.
- risk 0.40cvss 6.1epss 0.01
An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a crafted .shtml file.
- risk 0.40cvss 6.1epss 0.03
An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login route allows for injection of arbitrary JavaScript code into a web page's content, creating a Reflected XSS attack vector.
- risk 0.40cvss 6.1epss 0.01
Agentejo Cockpit has multiple Cross-Site Scripting vulnerabilities.
- risk 0.36cvss 5.5epss 0.00
A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infected PDF file and store a malicious JavaScript payload to be executed when the file is uploaded.
- risk 0.35cvss 5.4epss 0.01
Cockpit 0.5.5 has XSS via a collection, form, or region.
- risk 0.33cvss 6.1epss 0.02
Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.
- risk 0.33cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.
- risk 0.33cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.4.3.
- risk 0.29cvss 5.5epss 0.00
Use of Platform-Dependent Third Party Components in GitHub repository cockpit-hq/cockpit prior to 2.4.0.
- risk 0.28cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.
- risk 0.28cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.
- risk 0.28cvss 5.4epss 0.00
Improper Restriction of Rendered UI Layers or Frames in GitHub repository cockpit-hq/cockpit prior to 2.3.9-dev.
- risk 0.24cvss 4.8epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.
- risk 0.21cvss 3.2epss 0.00
A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pam_env's user_readenv option, which leads to a denial of service (DoS) attack.
- risk 0.16cvss 3.5epss 0.00
A vulnerability was found in Cockpit up to 2.11.3. It has been rated as problematic. This issue affects some unknown processing of the file /system/users/save. The manipulation of the argument name/email leads to cross site scripting. The attack may be initiated remotely.…
- risk 0.00cvss 5.3epss 0.00
A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2. Affected by this issue is the function Spyc::YAMLLoad of the file /config/config.yaml of the component htaccess Handler. Such manipulation leads to files or directories accessible. It is possible to…
- risk 0.00cvss 6.1epss 0.01
Cockpit is a content management system that allows addition of content management functionality to any site. In versions 0.12.2 and prior, bad HTML sanitization in `htmleditor.js` may lead to cross-site scripting (XSS) issues. There are no known patches for this issue.
Page 2 of 3