VYPR

Portainer

by Portainer

Source repositories

CVEs (29)

  • CVE-2026-44885MedMay 28, 2026
    risk 0.29cvss 5.5epss 0.01

    Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, Portainer's backup restore feature accepts a .tar.gz archive and…

  • CVE-2019-16873MedNov 7, 2019
    risk 0.28cvss 5.4epss 0.01

    Portainer before 1.22.1 has XSS (issue 1 of 2).

  • CVE-2026-55761MedJul 8, 2026
    risk 0.00cvss 5.9epss 0.00

    Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. In versions 2.39.0 through 2.39.3 and 2.40.0 until 2.43.0, unauthenticated restore and administrator…

  • CVE-2024-33661CriApr 26, 2024
    risk 0.00cvss 9.1epss 0.01

    Portainer before 2.20.0 allows redirects when the target is not index.yaml.

  • CVE-2022-24961CriFeb 11, 2022
    risk 0.00cvss 9.8epss 0.02

    In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days.

  • CVE-2021-42650MedOct 18, 2021
    risk 0.00cvss 6.1epss 0.01

    Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates.

  • CVE-2018-19466CriMar 27, 2019
    risk 0.00cvss 9.8epss 0.04

    A vulnerability was found in Portainer before 1.20.0. Portainer stores LDAP credentials, corresponding to a master password, in cleartext and allows their retrieval via API calls.

  • CVE-2018-16316MedSep 1, 2018
    risk 0.00cvss 5.4epss 0.01

    A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to inject arbitrary JavaScript and/or HTML via the Team Name field.

  • CVE-2018-12678CriJun 22, 2018
    risk 0.00cvss 9.8epss 0.02

    Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query parameter for the /websocket/exec endpoint, which allows remote attackers to bypass intended access restrictions or conduct SSRF attacks.

Page 2 of 2