Cyberpanel
22 CVEs tracked. 2 of them are in CISA KEV.
This hub aggregates every CVE we track for Cyberpanel, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
Cyberpanel CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 3 |
| 2024-11 | 0 |
| 2024-12 | 3 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 2 |
| 2026-05 | 1 |
| 2026-06 | 0 |
| 2026-07 | 2 |
| 2026-08 | 5 |
| 2026-09 | 5 |
Severity
How the 22 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical5
- High9
- Medium8
Latest CVEs
The 15 most recently published vulnerabilities affecting Cyberpanel.
- CVE-2026-29812CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.4.3
- CVE-2026-29810CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.4.3
- CVE-2026-29811CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a...7.7
- CVE-2026-88895CyberPanel before 3.0.5 Authentication Bypass via API7.2
- CVE-2026-87820CyberPanel 2.4.3 through 2.4.5 Information Disclosure via AI Scanner5.3
- CVE-2026-67613CyberPanel < 3.0.0 Path Traversal File Read via cloudAPI ReadReport4.9
- CVE-2026-67614CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal9.8
- CVE-2026-71966CyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransfer8.8
- CVE-2026-71965CyberPanel 2.4.3 Authenticated RCE via Remote Backup Feature8.8
- CVE-2026-71964CyberPanel 2.4.3 Arbitrary File Read via File Manager ZIP Upload6.5
- CVE-2026-65917CyberPanel IncBackups IDOR via Sequential Backup ID8.8
- CVE-2026-65916CyberPanel Missing Authorization in cancelBackupCreation Handler8.1
- CVE-2021-47949CyberPanel 2.1 Authenticated Remote Code Execution via Symlink Attack8.8
- CVE-2026-41473CyberPanel < 2.4.5 Unauthenticated API Access via AI Scanner Endpoints9.1
- CVE-2026-41472CyberPanel < 2.4.5 Stored XSS via AI Scanner Dashboard6.1
Product grouping is registry-driven, with AI assist and human review. How it works