CVE Tools

1panel-dev

26 CVEs tracked since 2023. Since Jul 2023, none of them reached CISA KEV.

1panel-dev CVEs per month

Jul 2023 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
1panel-dev CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2023-0750
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-04140
2026-05null or fewer
2026-06null or fewer
2026-07null or fewer
2026-08null or fewer
2026-0970

Products

The products that kept showing up in 1panel-dev's monthly top three, with their CVEs summed over those months.

  1. Maxkb141 month
  2. Cordyscrm71 month
  3. 1panel31 month
  4. Kubepi21 month

Latest CVEs

The 15 most recently published vulnerabilities affecting 1panel-dev.

  1. CVE-2026-79919MaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path callbacks and unhooked dlsym(RTLD_NEXT)6.3
  2. CVE-2026-79918MaxKB: Sandbox escape via unhooked fexecve6.3
  3. CVE-2026-77517MaxKB cross-knowledge IDOR lets a normal user read and modify documents and paragraphs in another knowledge base5.4
  4. CVE-2026-77521MaxKB: Prompt-injectable agent can lead to command execution10.0
  5. CVE-2026-77522MaxKB: Authenticated full-read SSRF via the knowledge web-document import/sync crawler (Fork.fork requests.get, no internal-IP guard, non-blind)4.3
  6. CVE-2026-79917MaxKB: Chat share-link endpoint missing owner check: a chat token can publish another user's conversation6.5
  7. CVE-2026-77516MaxKB: Missing per-tool authorization in the agent and workflow tool-dispatch path5.4
  8. CVE-2026-77523MaxKB: Cross-workspace model parameter form write7.4
  9. CVE-2026-77525MaxKB: Management chat-record routes trust path application_id but load ChatRecord by global chat_id4.2
  10. CVE-2026-77518MaxKB: Known MCP tool IDs expose owner Tool.code and can be referenced by attacker workflows5.0
  11. CVE-2026-79916MaxKB AWS Bedrock model credential injection leads to remote code execution9.1
  12. CVE-2026-77520MaxKB: Homepage ranking leaks application IDs that workflow application-nodes can use to invoke another user's application5.4
  13. CVE-2026-77519MaxKB: Expired application API keys remain usable on `/chat/api/mcp`5.4
  14. CVE-2026-76899CordysCRM: Authenticated SQL injection via `sort.name` on `POST /account-pool/page`5.7
  15. CVE-2026-76902CordysCRM: Unauthenticated arbitrary file disclosure via `/attachment/preview/{id}` and `/pic/preview/{id}`5.0

The record

Peak rank
#69 in Apr 2026
Busiest month shown
Apr 2026, 14 CVEs
Months with a KEV entry
0 since Jul 2023
Monthly snapshots
3 since 2023
1panel-dev's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store