VulnSea

cobbler has 13 CVEs on record between 2021 and 2022. The median CVSS is 7.5 (high), with 1 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
0 prev 0

Products

  • cobbler 13
13
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

cobbler vulnerabilities

CVEs affecting cobbler, newest first. Open any entry for full detail, references, and exploit status.

13 CVEsRSS

CVE-2008-6954High
4y ago

Cobbler Web Interface Kickstart Template Remote Privilege Escalation Vulnerability

Cobbler Web Interface Kickstart Template Remote Privilege Escalation Vulnerability

Twilightcobbler · cobblerEPSS 2.2%via OSV
CVE-2010-2235High
4y ago

Cobbler is vulnerable to code injection

Cobbler is vulnerable to code injection

Twilightcobbler · cobblerEPSS 3.4%via OSV
CVE-2011-4953Medium
4y ago

Cobbler vulnerable to code injection via unsafe YAML loading

Cobbler vulnerable to code injection via unsafe YAML loading

Sunlitcobbler · cobblerEPSS 2.2%via OSV
CVE-2012-2395High
4y ago

Cobbler subject to Command Injection

Cobbler subject to Command Injection

Twilightcobbler · cobblerEPSS 5.6%via OSV
CVE-2014-3225MediumPoC
4y ago

Cobbler Path Traversal vulnerability

Cobbler Path Traversal vulnerability

Twilightcobbler · cobblerEPSS 8.9%via OSV
CVE-2018-1000225Medium· 6.1
4y ago

Cobbler XSS Vulnerability

Cobbler XSS Vulnerability

Sunlitcobbler · cobblerEPSS 1.5%via OSV
CVE-2016-9605Medium· 6.1
4y ago

Cobbler Arbitrary File Read

Cobbler Arbitrary File Read

Sunlitcobbler · cobblerEPSS 0.81%via OSV
CVE-2011-4952High· 8.8
4y ago

Cobbler Web Interface Lacks CSRF Protection

Cobbler Web Interface Lacks CSRF Protection

Twilightcobbler · cobblerEPSS 0.64%via OSV
CVE-2021-45083High· 7.1
4y ago

Incorrect Default Permissions in Cobbler

Incorrect Default Permissions in Cobbler

Twilightcobbler · cobblerEPSS 0.31%via OSV
CVE-2021-45082High· 7.8
4y ago

Command Injection in Cobbler

Command Injection in Cobbler

Twilightcobbler · cobblerEPSS 0.50%via OSV
CVE-2021-40325High· 7.5
4y ago

Cobbler before 3.3.0 allows authorization bypass for modification of settings.

Cobbler before 3.3.0 allows authorization bypass for modification of settings.

Twilightcobbler · cobblerEPSS 1.4%via OSV
CVE-2021-40323Critical· 9.8PoC
4y ago

Cobbler before 3.3.0 allows log poisoning

Cobbler before 3.3.0 allows log poisoning

Abyssalcobbler · cobblerEPSS 87%via OSV
CVE-2021-40324High· 7.5
4y ago

Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.

Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.

Twilightcobbler · cobblerEPSS 69%via OSV
cobbler vulnerabilities (CVEs) · VulnSea