CVEs we hold for 1panel-dev
Records whose assigning authority named 1panel-dev as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-76902CordysCRM: Unauthenticated arbitrary file disclosure via `/attachment/preview/{id}` and `/pic/preview/{id}`1Panel-dev CordysCRM
CVE-2026-76901CordysCRM: Broken object-level authorization in lead pool and account pool detail endpoints exposes arbitrary leads and…1Panel-dev CordysCRM
CVE-2026-76900CordysCRM: SSRF via Approval Flow Webhook Execution due to Missing SSRF Validation at Runtime1Panel-dev CordysCRM
CVE-2026-76899CordysCRM: Authenticated SQL injection via `sort.name` on `POST /account-pool/page`1Panel-dev CordysCRM
CVE-2026-69129KubePi: Insufficient per-cluster authorization checks in cluster management APIs1Panel-dev KubePi
CVE-2026-65956KubePi: Unauthenticated SSO/OIDC configuration allows admin account takeover and SSRF1Panel-dev KubePi
CVE-2026-64870MaxKB: UpdateStoreTool fetches caller-supplied app-store URLs without host validation1Panel-dev MaxKB
CVE-2026-63646CordysCRM MCP Form Configuration Endpoint Exposed to Anonymous Users1Panel-dev CordysCRM
CVE-2026-61081Panel-dev MaxKB Model Context Protocol Node base_mcp_node.py execute os command injection1Panel-dev MaxKB
CVE-2026-61071Panel-dev MaxKB ChatHeadersMiddleware chat_headers_middleware.py cross site scripting1Panel-dev MaxKB
CVE-2026-61061Panel-dev MaxKB Public Chat static_headers_middleware.py StaticHeadersMiddleware cross site scripting1Panel-dev MaxKB
CVE-2026-56779MaxKB < 2.10.0 - Server-Side Request Forgery via downloadCallbackUrl and download_url Parameters1Panel-dev MaxKB
CVE-2026-54149MaxKB MCP tool import validation bypass allows post-authentication remote code execution1Panel-dev MaxKB
CVE-2026-42335MaxKB: SSRF Bypass in MaxKB OSS URL Fetch due to URL Parsing Discrepancy1Panel-dev MaxKB
CVE-2026-39425MaxKB: Stored XSS via Unsanitized html_rander Tags in Markdown Rendering1Panel-dev MaxKB
CVE-2026-162231Panel-dev CordysCRM Third Party Edit Endpoint IntegrationConfigService.java getSqlBotSrc server-side request forgery1Panel-dev CordysCRM
CVE-2026-162221Panel-dev CordysCRM Third Party Endpoint TokenService.java server-side request forgery1Panel-dev CordysCRM
CVE-2026-105671Panel-dev CordysCRM ModuleFormController ModuleFormService.java save cross site scripting1Panel-dev CordysCRM
CVE-2026-105141Panel-dev CordysCRM RequestParamTrimConfig.java cross site scripting1Panel-dev CordysCRM
CVE-2025-665081Panel IP Access Control Bypass via Untrusted X-Forwarded-For Headers1Panel-dev 1Panel
CVE-2025-544241Panel Agent Bypasses Certificate Verification Leading to Arbitrary Command Execution1Panel-dev 1Panel
CVE-2024-302571Panel's password verification is suspected to have a timing attack vulnerability1Panel-dev 1Panel
CVE-2023-399641Panel O&M management panel has a background arbitrary file reading vulnerability1Panel-dev 1Panel
CVE-2023-364581Panel vulnerable to ommand injection when entering the container terminal1Panel-dev 1Panel
CVE-2023-364571Panel vulnerable to command injection when adding container repositories1Panel-dev 1Panel
66 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.