Vendor CVEs
Agentejo
All CVEs
42 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-35131 | Cri | 0.68 | 9.8 | 0.51 | Jan 8, 2021 | Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI. | ||
| CVE-2020-35847 | Cri | 0.68 | 9.8 | 0.98 | Dec 30, 2020 | Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function. | ||
| CVE-2020-35846 | Cri | 0.67 | 9.8 | 0.93 | Dec 30, 2020 | Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function. | ||
| CVE-2020-35848 | Cri | 0.66 | 9.8 | 0.75 | Dec 30, 2020 | Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function. | ||
| CVE-2024-4825 | Cri | 0.64 | 9.8 | 0.01 | May 14, 2024 | A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker could upload files to the server, compromising the entire infrastructure. | ||
| CVE-2018-15540 | Cri | 0.64 | 9.8 | 0.02 | Oct 15, 2018 | Agentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse the file system to unintended locations and/or access arbitrary files, aka /media/api Directory Traversal. | ||
| CVE-2018-9302 | Cri | 0.63 | 9.1 | 0.09 | May 2, 2018 | SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter. NOTE: this vulnerability exists because of an incomplete fix for… | ||
| CVE-2017-14611 | Cri | 0.59 | 9.1 | 0.02 | Apr 10, 2018 | SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of the discontinued aheinze/fetch_url_contents component. | ||
| CVE-2026-34965 | Hig | 0.57 | 8.8 | 0.01 | Apr 29, 2026 | Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection endpoint that allows authenticated attackers with collection management privileges to inject arbitrary PHP code into collection rules parameters. Attackers can… | ||
| CVE-2023-37650 | Hig | 0.57 | 8.8 | 0.01 | Jul 20, 2023 | A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Administrator commands. | ||
| CVE-2022-2818 | Cri | 0.57 | 9.8 | 0.02 | Aug 15, 2022 | Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2. | ||
| CVE-2022-2713 | Cri | 0.57 | 9.8 | 0.01 | Aug 8, 2022 | Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0. | ||
| CVE-2018-15539 | Hig | 0.57 | 8.8 | 0.01 | Oct 15, 2018 | Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc. | ||
| CVE-2023-4195 | Hig | 0.50 | 8.8 | 0.01 | Aug 6, 2023 | PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3. | ||
| CVE-2023-1313 | Hig | 0.50 | 8.8 | 0.01 | Mar 10, 2023 | Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit prior to 2.4.1. | ||
| CVE-2023-0759 | Hig | 0.50 | 8.8 | 0.00 | Feb 9, 2023 | Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8. | ||
| CVE-2023-37649 | Hig | 0.49 | 7.5 | 0.01 | Jul 20, 2023 | Incorrect access control in the component /models/Content of Cockpit CMS v2.5.2 allows unauthorized attackers to access sensitive data. | ||
| CVE-2021-3698 | Hig | 0.49 | 7.5 | 0.01 | Mar 10, 2022 | A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL)… | ||
| CVE-2024-2947 | Hig | 0.48 | 7.3 | 0.01 | Mar 28, 2024 | A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer. | ||
| CVE-2026-4802 | Hig | 0.45 | 8.0 | 0.01 | May 11, 2026 | A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell… | ||
| CVE-2026-31891 | Hig | 0.43 | 7.7 | 0.00 | Mar 18, 2026 | Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API access enabled is potentially affected by a a SQL Injection vulnerability in the MongoLite Aggregation Optimizer. Any deployment where the… | ||
| CVE-2020-35850 | Med | 0.42 | 6.5 | 0.02 | Dec 30, 2020 | An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product. NOTE: the vendor states "I don't think [it] is a big real-life issue. | ||
| CVE-2023-41564 | Med | 0.40 | 6.1 | 0.01 | Sep 8, 2023 | An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a crafted .shtml file. | ||
| CVE-2020-14408 | Med | 0.40 | 6.1 | 0.03 | Jun 17, 2020 | An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login route allows for injection of arbitrary JavaScript code into a web page's content, creating a Reflected XSS attack vector. | ||
| CVE-2018-15538 | Med | 0.40 | 6.1 | 0.01 | Oct 15, 2018 | Agentejo Cockpit has multiple Cross-Site Scripting vulnerabilities. | ||
| CVE-2024-2001 | Med | 0.36 | 5.5 | 0.00 | Feb 29, 2024 | A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infected PDF file and store a malicious JavaScript payload to be executed when the file is uploaded. | ||
| CVE-2018-11471 | Med | 0.35 | 5.4 | 0.01 | May 25, 2018 | Cockpit 0.5.5 has XSS via a collection, form, or region. | ||
| CVE-2023-4451 | Med | 0.33 | 6.1 | 0.02 | Aug 20, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4. | ||
| CVE-2023-4432 | Med | 0.33 | 6.1 | 0.01 | Aug 19, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4. | ||
| CVE-2023-4321 | Med | 0.33 | 6.1 | 0.01 | Aug 14, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.4.3. | ||
| CVE-2023-1160 | Med | 0.29 | 5.5 | 0.00 | Mar 3, 2023 | Use of Platform-Dependent Third Party Components in GitHub repository cockpit-hq/cockpit prior to 2.4.0. | ||
| CVE-2023-4433 | Med | 0.28 | 5.4 | 0.00 | Aug 19, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4. | ||
| CVE-2023-4395 | Med | 0.28 | 5.4 | 0.01 | Aug 17, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4. | ||
| CVE-2023-4196 | Med | 0.28 | 5.4 | 0.00 | Aug 6, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3. | ||
| CVE-2023-0780 | Med | 0.28 | 5.4 | 0.00 | Feb 11, 2023 | Improper Restriction of Rendered UI Layers or Frames in GitHub repository cockpit-hq/cockpit prior to 2.3.9-dev. | ||
| CVE-2023-4422 | Med | 0.24 | 4.8 | 0.01 | Aug 18, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3. | ||
| CVE-2024-6126 | Low | 0.21 | 3.2 | 0.00 | Jul 3, 2024 | A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pam_env's user_readenv option, which leads to a denial of service (DoS) attack. | ||
| CVE-2025-7053 | Low | 0.16 | 3.5 | 0.00 | Jul 4, 2025 | A vulnerability was found in Cockpit up to 2.11.3. It has been rated as problematic. This issue affects some unknown processing of the file /system/users/save. The manipulation of the argument name/email leads to cross site scripting. The attack may be initiated remotely.… | ||
| CVE-2026-13533 | Med | 0.00 | 5.3 | 0.00 | Jun 29, 2026 | A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2. Affected by this issue is the function Spyc::YAMLLoad of the file /config/config.yaml of the component htaccess Handler. Such manipulation leads to files or directories accessible. It is possible to… | ||
| CVE-2021-32857 | Med | 0.00 | 6.1 | 0.01 | Feb 21, 2023 | Cockpit is a content management system that allows addition of content management functionality to any site. In versions 0.12.2 and prior, bad HTML sanitization in `htmleditor.js` may lead to cross-site scripting (XSS) issues. There are no known patches for this issue. | ||
| CVE-2021-3660 | Med | 0.00 | 4.3 | 0.01 | Mar 10, 2022 | Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an HTML entry. This may be used by a malicious website in clickjacking or similar attacks. | ||
| CVE-2019-3804 | Hig | 0.00 | 7.5 | 0.05 | Mar 26, 2019 | It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to… |
- risk 0.68cvss 9.8epss 0.51
Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI.
- risk 0.68cvss 9.8epss 0.98
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
- risk 0.67cvss 9.8epss 0.93
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.
- risk 0.66cvss 9.8epss 0.75
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
- risk 0.64cvss 9.8epss 0.01
A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker could upload files to the server, compromising the entire infrastructure.
- risk 0.64cvss 9.8epss 0.02
Agentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse the file system to unintended locations and/or access arbitrary files, aka /media/api Directory Traversal.
- risk 0.63cvss 9.1epss 0.09
SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter. NOTE: this vulnerability exists because of an incomplete fix for…
- risk 0.59cvss 9.1epss 0.02
SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of the discontinued aheinze/fetch_url_contents component.
- risk 0.57cvss 8.8epss 0.01
Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection endpoint that allows authenticated attackers with collection management privileges to inject arbitrary PHP code into collection rules parameters. Attackers can…
- risk 0.57cvss 8.8epss 0.01
A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Administrator commands.
- risk 0.57cvss 9.8epss 0.02
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2.
- risk 0.57cvss 9.8epss 0.01
Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.
- risk 0.57cvss 8.8epss 0.01
Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc.
- risk 0.50cvss 8.8epss 0.01
PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3.
- risk 0.50cvss 8.8epss 0.01
Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit prior to 2.4.1.
- risk 0.50cvss 8.8epss 0.00
Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8.
- risk 0.49cvss 7.5epss 0.01
Incorrect access control in the component /models/Content of Cockpit CMS v2.5.2 allows unauthorized attackers to access sensitive data.
- risk 0.49cvss 7.5epss 0.01
A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL)…
- risk 0.48cvss 7.3epss 0.01
A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.
- risk 0.45cvss 8.0epss 0.01
A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell…
- risk 0.43cvss 7.7epss 0.00
Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API access enabled is potentially affected by a a SQL Injection vulnerability in the MongoLite Aggregation Optimizer. Any deployment where the…
- risk 0.42cvss 6.5epss 0.02
An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product. NOTE: the vendor states "I don't think [it] is a big real-life issue.
- risk 0.40cvss 6.1epss 0.01
An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a crafted .shtml file.
- risk 0.40cvss 6.1epss 0.03
An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login route allows for injection of arbitrary JavaScript code into a web page's content, creating a Reflected XSS attack vector.
- risk 0.40cvss 6.1epss 0.01
Agentejo Cockpit has multiple Cross-Site Scripting vulnerabilities.
- risk 0.36cvss 5.5epss 0.00
A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infected PDF file and store a malicious JavaScript payload to be executed when the file is uploaded.
- risk 0.35cvss 5.4epss 0.01
Cockpit 0.5.5 has XSS via a collection, form, or region.
- risk 0.33cvss 6.1epss 0.02
Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.
- risk 0.33cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.
- risk 0.33cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.4.3.
- risk 0.29cvss 5.5epss 0.00
Use of Platform-Dependent Third Party Components in GitHub repository cockpit-hq/cockpit prior to 2.4.0.
- risk 0.28cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.
- risk 0.28cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.
- risk 0.28cvss 5.4epss 0.00
Improper Restriction of Rendered UI Layers or Frames in GitHub repository cockpit-hq/cockpit prior to 2.3.9-dev.
- risk 0.24cvss 4.8epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.
- risk 0.21cvss 3.2epss 0.00
A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pam_env's user_readenv option, which leads to a denial of service (DoS) attack.
- risk 0.16cvss 3.5epss 0.00
A vulnerability was found in Cockpit up to 2.11.3. It has been rated as problematic. This issue affects some unknown processing of the file /system/users/save. The manipulation of the argument name/email leads to cross site scripting. The attack may be initiated remotely.…
- risk 0.00cvss 5.3epss 0.00
A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2. Affected by this issue is the function Spyc::YAMLLoad of the file /config/config.yaml of the component htaccess Handler. Such manipulation leads to files or directories accessible. It is possible to…
- risk 0.00cvss 6.1epss 0.01
Cockpit is a content management system that allows addition of content management functionality to any site. In versions 0.12.2 and prior, bad HTML sanitization in `htmleditor.js` may lead to cross-site scripting (XSS) issues. There are no known patches for this issue.
- risk 0.00cvss 4.3epss 0.01
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
- risk 0.00cvss 7.5epss 0.05
It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to…