VYPR

Cockpit

by Agentejo

Source repositories

CVEs (42)

  • CVE-2026-31891HigMar 18, 2026
    risk 0.43cvss 7.7epss 0.00

    Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API access enabled is potentially affected by a a SQL Injection vulnerability in the MongoLite Aggregation Optimizer. Any deployment where the…

  • CVE-2020-35850MedDec 30, 2020
    risk 0.42cvss 6.5epss 0.02

    An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product. NOTE: the vendor states "I don't think [it] is a big real-life issue.

  • CVE-2023-41564MedSep 8, 2023
    risk 0.40cvss 6.1epss 0.01

    An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a crafted .shtml file.

  • CVE-2020-14408MedJun 17, 2020
    risk 0.40cvss 6.1epss 0.03

    An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login route allows for injection of arbitrary JavaScript code into a web page's content, creating a Reflected XSS attack vector.

  • CVE-2018-15538MedOct 15, 2018
    risk 0.40cvss 6.1epss 0.01

    Agentejo Cockpit has multiple Cross-Site Scripting vulnerabilities.

  • CVE-2024-2001MedFeb 29, 2024
    risk 0.36cvss 5.5epss 0.00

    A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infected PDF file and store a malicious JavaScript payload to be executed when the file is uploaded.

  • CVE-2018-11471MedMay 25, 2018
    risk 0.35cvss 5.4epss 0.01

    Cockpit 0.5.5 has XSS via a collection, form, or region.

  • CVE-2023-4451MedAug 20, 2023
    risk 0.33cvss 6.1epss 0.02

    Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

  • CVE-2023-4432MedAug 19, 2023
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

  • CVE-2023-4321MedAug 14, 2023
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.4.3.

  • CVE-2023-1160MedMar 3, 2023
    risk 0.29cvss 5.5epss 0.00

    Use of Platform-Dependent Third Party Components in GitHub repository cockpit-hq/cockpit prior to 2.4.0.

  • CVE-2023-4433MedAug 19, 2023
    risk 0.28cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

  • CVE-2023-4395MedAug 17, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

  • CVE-2023-4196MedAug 6, 2023
    risk 0.28cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.

  • CVE-2023-0780MedFeb 11, 2023
    risk 0.28cvss 5.4epss 0.00

    Improper Restriction of Rendered UI Layers or Frames in GitHub repository cockpit-hq/cockpit prior to 2.3.9-dev.

  • CVE-2023-4422MedAug 18, 2023
    risk 0.24cvss 4.8epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.

  • CVE-2024-6126LowJul 3, 2024
    risk 0.21cvss 3.2epss 0.00

    A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pam_env's user_readenv option, which leads to a denial of service (DoS) attack.

  • CVE-2025-7053LowJul 4, 2025
    risk 0.16cvss 3.5epss 0.00

    A vulnerability was found in Cockpit up to 2.11.3. It has been rated as problematic. This issue affects some unknown processing of the file /system/users/save. The manipulation of the argument name/email leads to cross site scripting. The attack may be initiated remotely.…

  • CVE-2026-13533MedJun 29, 2026
    risk 0.00cvss 5.3epss 0.00

    A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2. Affected by this issue is the function Spyc::YAMLLoad of the file /config/config.yaml of the component htaccess Handler. Such manipulation leads to files or directories accessible. It is possible to…

  • CVE-2021-32857MedFeb 21, 2023
    risk 0.00cvss 6.1epss 0.01

    Cockpit is a content management system that allows addition of content management functionality to any site. In versions 0.12.2 and prior, bad HTML sanitization in `htmleditor.js` may lead to cross-site scripting (XSS) issues. There are no known patches for this issue.