Cyberpanel
This hub aggregates every CVE we track for Cyberpanel, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
22
CVEs tracked
5
Critical
9
High
2
In CISA KEV
Severity distribution
HIGH9MEDIUM8CRITICAL5
Monthly trend
3
0
3
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2
1
0
2
5
5
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Cyberpanel.
- CVE-2026-29812CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.4.3
- CVE-2026-29810CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.4.3
- CVE-2026-29811CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a...7.7
- CVE-2026-88895CyberPanel before 3.0.5 Authentication Bypass via API7.2
- CVE-2026-87820CyberPanel 2.4.3 through 2.4.5 Information Disclosure via AI Scanner5.3
- CVE-2026-67613CyberPanel < 3.0.0 Path Traversal File Read via cloudAPI ReadReport4.9
- CVE-2026-67614CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal9.8
- CVE-2026-71966CyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransfer8.8
- CVE-2026-71965CyberPanel 2.4.3 Authenticated RCE via Remote Backup Feature8.8
- CVE-2026-71964CyberPanel 2.4.3 Arbitrary File Read via File Manager ZIP Upload6.5
- CVE-2026-65917CyberPanel IncBackups IDOR via Sequential Backup ID8.8
- CVE-2026-65916CyberPanel Missing Authorization in cancelBackupCreation Handler8.1
- CVE-2021-47949CyberPanel 2.1 Authenticated Remote Code Execution via Symlink Attack8.8
- CVE-2026-41473CyberPanel < 2.4.5 Unauthenticated API Access via AI Scanner Endpoints9.1
- CVE-2026-41472CyberPanel < 2.4.5 Stored XSS via AI Scanner Dashboard6.1
Product normalization is registry-driven with AI assist and human review. How it works