VulnSea

Cockpit-HQ has 3 CVEs on record. 2 were published in the last 90 days. The median CVSS is 5.3 (medium).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
5.3
Publish → KEV
—
Last 90 days
2 prev 1

Products

  • cockpit 3
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

Cockpit-HQ vulnerabilities

CVEs affecting Cockpit-HQ, newest first. Open any entry for full detail, references, and exploit status.

3 CVEsRSS

CVE-2026-105217Low· 3.1
5d ago

Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to capture the worker token

Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to capture the worker token. Man-in-the-middle attackers on the outbound path to site_url can p…

▾ Sunlitcockpit-hq · cockpitEPSS 0.10%via NVD
CVE-2026-82449Medium· 5.3
1mo ago

Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrepancies in password verification

Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrepancies in password verification. Attackers can measure response times across multiple requests to determine which acc…

▾ Sunlitcockpit-hq · cockpitEPSS 0.42%via NVD
CVE-2026-23695Medium· 5.4
4mo ago

Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a stored cross-site scripting vulnerability in the Set field type's Display template option, where the template string is processed by the $interpolate function usin…

Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a stored cross-site scripting vulnerability in the Set field type's Display template option, where the template string is processed by the $interpolate function usin…

▾ SunlitCockpit-HQ · CockpitEPSS 0.14%via NVD
Cockpit-HQ vulnerabilities (CVEs) · VulnSea