VYPR

Cockpit Hq/cockpit

by Cockpit Hq

Source repositories

CVEs (34)

  • CVE-2023-4321MedAug 14, 2023
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.4.3.

  • CVE-2023-1160MedMar 3, 2023
    risk 0.29cvss 5.5epss 0.00

    Use of Platform-Dependent Third Party Components in GitHub repository cockpit-hq/cockpit prior to 2.4.0.

  • CVE-2026-23695MedMay 15, 2026
    risk 0.28cvss 5.4epss 0.00

    Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a stored cross-site scripting vulnerability in the Set field type's Display template option, where the template string is processed by the $interpolate function using new Function() and rendered via Vue's…

  • CVE-2023-4433MedAug 19, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

  • CVE-2023-4395MedAug 17, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

  • CVE-2023-4196MedAug 6, 2023
    risk 0.28cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.

  • CVE-2023-0780MedFeb 11, 2023
    risk 0.28cvss 5.4epss 0.00

    Improper Restriction of Rendered UI Layers or Frames in GitHub repository cockpit-hq/cockpit prior to 2.3.9-dev.

  • CVE-2026-82449MedAug 29, 2026
    risk 0.27cvss 5.3epss 0.00

    Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrepancies in password verification. Attackers can measure response times across multiple requests to determine which accounts exist by observing that existing…

  • CVE-2023-4422MedAug 18, 2023
    risk 0.24cvss 4.8epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.

  • CVE-2026-91142LowSep 18, 2026
    risk 0.23cvss 3.6epss 0.00

    A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offset calculation for `lastlog` entries on ILP32 (Integer, Long, Pointer 32-bit) builds, can be exploited. A low-privileged authenticated user with a specially…

  • CVE-2026-57856HigJul 13, 2026
    risk 0.00cvss 8.8epss 0.01

    Cockpit CMS contains a path traversal vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php sanitizes the bucket name with preg_replace('/[^a-zA-Z0-9-_\\.]/','', $bucket), which permits '..' and '../'…

  • CVE-2026-57855HigJul 13, 2026
    risk 0.00cvss 8.8epss 0.01

    Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php executes bucket commands (ls, upload, removefiles, rename, createfolder) without performing any ACL or role…

  • CVE-2021-3660MedMar 10, 2022
    risk 0.00cvss 4.3epss 0.01

    Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

  • CVE-2019-3804HigMar 26, 2019
    risk 0.00cvss 7.5epss 0.05

    It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to…

Page 2 of 2