VYPR
Vendor

OpenPanel

Products
3
CVEs
14
Across products
15
Status
Private

Products

3

Recent CVEs

14
  • CVE-2024-53584CriJan 31, 2025
    risk 0.67cvss 9.8epss 0.04

    OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.

  • CVE-2024-53537CriJan 31, 2025
    risk 0.62cvss 9.1epss 0.02

    An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager.

  • CVE-2026-85610HigSep 4, 2026
    risk 0.57cvss 8.8epss 0.00

    OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project members with read access to execute arbitrary code by recovering the native JavaScript Function constructor through mathjs matrix objects. Attackers can use the recovered…

  • CVE-2026-85614HigSep 4, 2026
    risk 0.56cvss 8.6epss 0.00

    OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker endpoint that accepts a fully client-controlled URL parameter with no private IP filtering or DNS-rebinding protection. Attackers can make the OpenPanel…

  • CVE-2026-85613HigSep 4, 2026
    risk 0.53cvss 8.2epss 0.00

    OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote attackers to execute scripts by supplying an SVG file URL. Attackers can host malicious SVG files with embedded scripts that…

  • CVE-2025-25871HigMar 14, 2025
    risk 0.52cvss 8.0epss 0.00

    An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function

  • CVE-2024-53582HigJan 31, 2025
    risk 0.52cvss 7.5epss 0.03

    An issue found in the Copy and View functions in the File Manager component of OpenPanel v0.3.4 allows attackers to execute a directory traversal via a crafted HTTP request.

  • CVE-2026-85612HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints that accept an attacker-supplied url parameter with insufficient validation. Attackers can force the API to fetch arbitrary internal hosts and…

  • CVE-2026-85609HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    Openpanel before 2.3.0 contains an unauthenticated full-read server-side request forgery (SSRF) vulnerability in the GET /tools/site-checker endpoint (apps/api/src/controllers/tools.controller.ts). The endpoint passes a user-supplied url query parameter to fetchWithRedirects()…

  • CVE-2026-85611MedSep 4, 2026
    risk 0.42cvss 6.4epss 0.00

    OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to scope dashboard queries to the caller's project. Authenticated attackers can supply their own projectId…

  • CVE-2025-25873MedMar 14, 2025
    risk 0.36cvss 5.5epss 0.00

    Cross Site Request Forgery vulnerability in Open Panel OpenAdmin v.0.3.4 allows a remote attacker to escalate privileges via the Change Root Password function

  • CVE-2025-25872MedMar 14, 2025
    risk 0.36cvss 5.5epss 0.00

    An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function

  • CVE-2026-77769MedAug 21, 2026
    risk 0.35cvss 6.5epss 0.00

    The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned getReportsByDashboardId(dashboardId). The enforceAccess middleware in packages/trpc/src/trpc.ts verified membership for the supplied projectId, but nothing…

  • CVE-2026-77768MedAug 21, 2026
    risk 0.35cvss 6.5epss 0.00

    The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returned getReportById(reportId) directly. The enforceAccess middleware in packages/trpc/src/trpc.ts evaluates membership only when the input carries a projectId or organizationId key,…