VulnSea

cyberpanel has 5 CVEs on record between 2024 and 2026. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 7.7 (high), with 2 rated critical. 40% have been exploited in the wild — well above the 1% corpus average, so cyberpanel flaws are worth patching on sight.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
40% vs 1% corpus
Median CVSS
7.7
Publish → KEV
(2)
Last 90 days
3 prev 0

Products

  • CyberPanel 5
5
Total CVEs
2
Critical
2
CISA KEV
2
Exploited

cyberpanel vulnerabilities

CVEs affecting cyberpanel, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-29811High· 7.7
1w ago

CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.

CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.

TwilightCyberPanel · CyberPanelEPSS 0.25%via NVD
CVE-2026-29810Medium· 4.3
1w ago

CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.

CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.

SunlitCyberPanel · CyberPanelEPSS 0.30%via NVD
CVE-2026-29812Medium· 4.3
1w ago

CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.

CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.

SunlitCyberPanel · CyberPanelEPSS 0.22%via NVD
CVE-2024-51378Critical· 10.0CISA KEV0dayPoC
1y ago

getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…

getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…

Hadalcyberpanel · cyberpanelEPSS 95%via NVD
CVE-2024-51567Critical· 10.0CISA KEV0dayPoC
1y ago

upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which i…

upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which i…

Hadalcyberpanel · cyberpanelEPSS 87%via NVD
cyberpanel vulnerabilities (CVEs) · VulnSea