VYPR

Cockpit Hq/cockpit

by Cockpit Hq

Source repositories

CVEs (30)

  • CVE-2020-35131CriJan 8, 2021
    risk 0.68cvss 9.8epss 0.51

    Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI.

  • CVE-2018-9302CriMay 2, 2018
    risk 0.63cvss 9.1epss 0.09

    SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter. NOTE: this vulnerability exists because of an incomplete fix for…

  • CVE-2017-14611CriApr 10, 2018
    risk 0.59cvss 9.1epss 0.02

    SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of the discontinued aheinze/fetch_url_contents component.

  • CVE-2026-34965HigApr 29, 2026
    risk 0.57cvss 8.8epss 0.01

    Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection endpoint that allows authenticated attackers with collection management privileges to inject arbitrary PHP code into collection rules parameters. Attackers can…

  • CVE-2022-2818CriAug 15, 2022
    risk 0.57cvss 9.8epss 0.02

    Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2.

  • CVE-2022-2713CriAug 8, 2022
    risk 0.57cvss 9.8epss 0.01

    Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.

  • CVE-2026-73680HigAug 14, 2026
    risk 0.50cvss 8.8epss

    Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated users with only the assets/upload permission to execute arbitrary commands by uploading a video file with a shell metacharacter-laden filename. The…

  • CVE-2026-72557HigAug 11, 2026
    risk 0.50cvss 8.8epss 0.00

    An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extension including PHP scripts via the asset upload endpoint. The allowed_uploads configuration defaults to wildcard (*) and uploaded files are stored in a…

  • CVE-2023-4195HigAug 6, 2023
    risk 0.50cvss 8.8epss 0.01

    PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3.

  • CVE-2023-1313HigMar 10, 2023
    risk 0.50cvss 8.8epss 0.01

    Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit prior to 2.4.1.

  • CVE-2023-0759HigFeb 9, 2023
    risk 0.50cvss 8.8epss 0.00

    Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8.

  • CVE-2021-3698HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL)…

  • CVE-2026-4802HigMay 11, 2026
    risk 0.45cvss 8.0epss 0.01

    A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell…

  • CVE-2026-31891HigMar 18, 2026
    risk 0.43cvss 7.7epss 0.00

    Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API access enabled is potentially affected by a a SQL Injection vulnerability in the MongoLite Aggregation Optimizer. Any deployment where the…

  • CVE-2026-58467HigJul 2, 2026
    risk 0.42cvss 7.5epss 0.00

    Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files or execute PHP files by including unvalidated PATH_INFO derived from REQUEST_URI in filesystem path construction without…

  • CVE-2018-11471MedMay 25, 2018
    risk 0.35cvss 5.4epss 0.01

    Cockpit 0.5.5 has XSS via a collection, form, or region.

  • CVE-2023-4451MedAug 20, 2023
    risk 0.33cvss 6.1epss 0.02

    Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

  • CVE-2023-4432MedAug 19, 2023
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

  • CVE-2023-4321MedAug 14, 2023
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.4.3.

  • CVE-2023-1160MedMar 3, 2023
    risk 0.29cvss 5.5epss 0.00

    Use of Platform-Dependent Third Party Components in GitHub repository cockpit-hq/cockpit prior to 2.4.0.

Page 1 of 2