Cyberpanel
This hub aggregates every CVE we track for Cyberpanel, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
17
CVEs tracked
5
Critical
7
High
2
In CISA KEV
Severity distribution
HIGH7MEDIUM5CRITICAL5
Monthly trend
0
3
0
3
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2
1
0
2
5
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Cyberpanel.
- CVE-2026-67613CyberPanel < 3.0.0 Path Traversal File Read via cloudAPI ReadReport4.9
- CVE-2026-67614CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal9.8
- CVE-2026-71966CyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransfer8.8
- CVE-2026-71965CyberPanel 2.4.3 Authenticated RCE via Remote Backup Feature8.8
- CVE-2026-71964CyberPanel 2.4.3 Arbitrary File Read via File Manager ZIP Upload6.5
- CVE-2026-65917CyberPanel IncBackups IDOR via Sequential Backup ID8.8
- CVE-2026-65916CyberPanel Missing Authorization in cancelBackupCreation Handler8.1
- CVE-2021-47949CyberPanel 2.1 Authenticated Remote Code Execution via Symlink Attack8.8
- CVE-2026-41473CyberPanel < 2.4.5 Unauthenticated API Access via AI Scanner Endpoints9.1
- CVE-2026-41472CyberPanel < 2.4.5 Stored XSS via AI Scanner Dashboard6.1
- CVE-2024-53376CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the websites/submitWebsiteCreation URI.8.8
- CVE-2024-56112CyberPanel (aka Cyber Panel) before f0cf648 allows XSS via token or username to plogical/phpmyadminsignin.php.6.1
- CVE-2024-54679CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.4.3
- CVE-2024-51568CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthen...10.0
- CVE-2024-51567upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlst...KEV10.0
Product normalization is registry-driven with AI assist and human review. How it works