CyberPanel has 5 CVEs on record between 2024 and 2026. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 7.7 (high), with 2 rated critical. 40% have been exploited in the wild — well above the 1% corpus average, so CyberPanel flaws are worth patching on sight.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 40% vs 1% corpus
- Median CVSS
- 7.7
- Publish → KEV
- —(2)
- Last 90 days
- 3 prev 0
Weakness classes
Products
- CyberPanel 5
Worst active — by depth score
CVE-2024-51567Critical· 10.0upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which i…100CVE-2024-51378Critical· 10.0getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…100CVE-2026-29811High· 7.7CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.42CVE-2026-29812Medium· 4.3CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.24CVE-2026-29810Medium· 4.3CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.24
CyberPanel vulnerabilities
CVEs affecting CyberPanel, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-29811High· 7.7CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.
CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.
CVE-2026-29810Medium· 4.3CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.
CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.
CVE-2026-29812Medium· 4.3CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.
CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.
CVE-2024-51378Critical· 10.0CISA KEV0dayPoCgetresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…
CVE-2024-51567Critical· 10.0CISA KEV0dayPoCupgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which i…
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which i…