Pterodactyl/panel
This hub aggregates every CVE we track for Pterodactyl/panel, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
11
CVEs tracked
1
Critical
3
High
0
In CISA KEV
Severity distribution
MEDIUM7HIGH3CRITICAL1
Monthly trend
0
1
0
0
0
0
0
0
0
1
0
0
0
0
0
0
3
1
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 11 most recently published vulnerabilities affecting Pterodactyl/panel.
- CVE-2026-26016Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization8.1
- CVE-2025-69198Pterodactyl's improper resource locking allows raced queries to create more resources than alloted6.5
- CVE-2025-69197Pterodactyl TOTPs can be reused during validity window6.5
- CVE-2025-68954Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced5.4
- CVE-2025-49132Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution10.0
- CVE-2024-49762Pterodactyl Panel has plain-text logging of user passwords when two-factor authentication is disabled4.6
- CVE-2024-34067Multiple cross site scripting (XSS) vulnerabilities in the admin area of Pterodactyl panel6.1
- CVE-2021-41273Cross-Site Request Forgery allowing sending of test emails and generation of node auto-deployment keys4.3
- CVE-2021-41176logout CSRF in Pterodactyl Panel4.3
- CVE-2021-41129Authentication bypass in Pterodactyl8.1
- CVE-2019-1020002Pterodactyl before 0.7.14 with 2FA allows credential sniffing.7.5
Product normalization is registry-driven with AI assist and human review. How it works