VulnSea

cyberpanel vulnerabilities

CVEs whose affected-version data names the cyberpanel package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

7 CVEsRSS

CVE-2026-29811High· 7.7
1w ago

CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.

CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.

TwilightCyberPanel · CyberPanelEPSS 0.25%via NVD
CVE-2026-29810Medium· 4.3
1w ago

CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.

CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.

SunlitCyberPanel · CyberPanelEPSS 0.30%via NVD
CVE-2026-29812Medium· 4.3
1w ago

CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.

CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.

SunlitCyberPanel · CyberPanelEPSS 0.22%via NVD
CVE-2026-88895High· 7.2
1w ago

CyberPanel before 3.0.5 Authentication Bypass via API

CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and…

Twilightusmannasir · cyberpanelEPSS 0.43%via CVEORG
CVE-2026-87820Medium· 5.3PoC
1w ago

CyberPanel versions 2.4.3 through 2.4.5 expose unauthenticated AI Scanner debugging endpoints that disclose administrator usernames, API-key prefixes, scan identifiers, target domains, and account metadata

CyberPanel versions 2.4.3 through 2.4.5 expose unauthenticated AI Scanner debugging endpoints that disclose administrator usernames, API-key prefixes, scan identifiers, target domains, and account metadata. Unauthenticated attackers can …

Twilightusmannasir · cyberpanelEPSS 0.52%via NVD
CVE-2024-51378Critical· 10.0CISA KEV0dayPoC
1y ago

getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…

getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…

Hadalcyberpanel · cyberpanelEPSS 95%via NVD
CVE-2024-51567Critical· 10.0CISA KEV0dayPoC
1y ago

upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which i…

upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which i…

Hadalcyberpanel · cyberpanelEPSS 87%via NVD
cyberpanel vulnerabilities (CVEs) · VulnSea