VYPR

Vendor CVEs

Agentejo

All CVEs

42 total · sorted by risk
  • CVE-2020-35131CriJan 8, 2021
    risk 0.68cvss 9.8epss 0.51

    Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI.

  • CVE-2020-35847CriDec 30, 2020
    risk 0.68cvss 9.8epss 0.98

    Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.

  • CVE-2020-35846CriDec 30, 2020
    risk 0.67cvss 9.8epss 0.93

    Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.

  • CVE-2020-35848CriDec 30, 2020
    risk 0.66cvss 9.8epss 0.75

    Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.

  • CVE-2024-4825CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker could upload files to the server, compromising the entire infrastructure.

  • CVE-2018-15540CriOct 15, 2018
    risk 0.64cvss 9.8epss 0.02

    Agentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse the file system to unintended locations and/or access arbitrary files, aka /media/api Directory Traversal.

  • CVE-2018-9302CriMay 2, 2018
    risk 0.63cvss 9.1epss 0.09

    SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter. NOTE: this vulnerability exists because of an incomplete fix for…

  • CVE-2017-14611CriApr 10, 2018
    risk 0.59cvss 9.1epss 0.02

    SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of the discontinued aheinze/fetch_url_contents component.

  • CVE-2026-34965HigApr 29, 2026
    risk 0.57cvss 8.8epss 0.01

    Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection endpoint that allows authenticated attackers with collection management privileges to inject arbitrary PHP code into collection rules parameters. Attackers can…

  • CVE-2023-37650HigJul 20, 2023
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Administrator commands.

  • CVE-2022-2818CriAug 15, 2022
    risk 0.57cvss 9.8epss 0.02

    Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2.

  • CVE-2022-2713CriAug 8, 2022
    risk 0.57cvss 9.8epss 0.01

    Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.

  • CVE-2018-15539HigOct 15, 2018
    risk 0.57cvss 8.8epss 0.01

    Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc.

  • CVE-2023-4195HigAug 6, 2023
    risk 0.50cvss 8.8epss 0.01

    PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3.

  • CVE-2023-1313HigMar 10, 2023
    risk 0.50cvss 8.8epss 0.01

    Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit prior to 2.4.1.

  • CVE-2023-0759HigFeb 9, 2023
    risk 0.50cvss 8.8epss 0.00

    Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8.

  • CVE-2023-37649HigJul 20, 2023
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the component /models/Content of Cockpit CMS v2.5.2 allows unauthorized attackers to access sensitive data.

  • CVE-2021-3698HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL)…

  • CVE-2024-2947HigMar 28, 2024
    risk 0.48cvss 7.3epss 0.01

    A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.

  • CVE-2026-4802HigMay 11, 2026
    risk 0.45cvss 8.0epss 0.01

    A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell…

  • CVE-2026-31891HigMar 18, 2026
    risk 0.43cvss 7.7epss 0.00

    Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API access enabled is potentially affected by a a SQL Injection vulnerability in the MongoLite Aggregation Optimizer. Any deployment where the…

  • CVE-2020-35850MedDec 30, 2020
    risk 0.42cvss 6.5epss 0.02

    An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product. NOTE: the vendor states "I don't think [it] is a big real-life issue.

  • CVE-2023-41564MedSep 8, 2023
    risk 0.40cvss 6.1epss 0.01

    An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a crafted .shtml file.

  • CVE-2020-14408MedJun 17, 2020
    risk 0.40cvss 6.1epss 0.03

    An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login route allows for injection of arbitrary JavaScript code into a web page's content, creating a Reflected XSS attack vector.

  • CVE-2018-15538MedOct 15, 2018
    risk 0.40cvss 6.1epss 0.01

    Agentejo Cockpit has multiple Cross-Site Scripting vulnerabilities.

  • CVE-2024-2001MedFeb 29, 2024
    risk 0.36cvss 5.5epss 0.00

    A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infected PDF file and store a malicious JavaScript payload to be executed when the file is uploaded.

  • CVE-2018-11471MedMay 25, 2018
    risk 0.35cvss 5.4epss 0.01

    Cockpit 0.5.5 has XSS via a collection, form, or region.

  • CVE-2023-4451MedAug 20, 2023
    risk 0.33cvss 6.1epss 0.02

    Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

  • CVE-2023-4432MedAug 19, 2023
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

  • CVE-2023-4321MedAug 14, 2023
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.4.3.

  • CVE-2023-1160MedMar 3, 2023
    risk 0.29cvss 5.5epss 0.00

    Use of Platform-Dependent Third Party Components in GitHub repository cockpit-hq/cockpit prior to 2.4.0.

  • CVE-2023-4433MedAug 19, 2023
    risk 0.28cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

  • CVE-2023-4395MedAug 17, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

  • CVE-2023-4196MedAug 6, 2023
    risk 0.28cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.

  • CVE-2023-0780MedFeb 11, 2023
    risk 0.28cvss 5.4epss 0.00

    Improper Restriction of Rendered UI Layers or Frames in GitHub repository cockpit-hq/cockpit prior to 2.3.9-dev.

  • CVE-2023-4422MedAug 18, 2023
    risk 0.24cvss 4.8epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.

  • CVE-2024-6126LowJul 3, 2024
    risk 0.21cvss 3.2epss 0.00

    A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pam_env's user_readenv option, which leads to a denial of service (DoS) attack.

  • CVE-2025-7053LowJul 4, 2025
    risk 0.16cvss 3.5epss 0.00

    A vulnerability was found in Cockpit up to 2.11.3. It has been rated as problematic. This issue affects some unknown processing of the file /system/users/save. The manipulation of the argument name/email leads to cross site scripting. The attack may be initiated remotely.…

  • CVE-2026-13533MedJun 29, 2026
    risk 0.00cvss 5.3epss 0.00

    A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2. Affected by this issue is the function Spyc::YAMLLoad of the file /config/config.yaml of the component htaccess Handler. Such manipulation leads to files or directories accessible. It is possible to…

  • CVE-2021-32857MedFeb 21, 2023
    risk 0.00cvss 6.1epss 0.01

    Cockpit is a content management system that allows addition of content management functionality to any site. In versions 0.12.2 and prior, bad HTML sanitization in `htmleditor.js` may lead to cross-site scripting (XSS) issues. There are no known patches for this issue.

  • CVE-2021-3660MedMar 10, 2022
    risk 0.00cvss 4.3epss 0.01

    Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

  • CVE-2019-3804HigMar 26, 2019
    risk 0.00cvss 7.5epss 0.05

    It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to…