vciy

CVEs we hold for 1panel-dev

Records whose assigning authority named 1panel-dev as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-76902CordysCRM: Unauthenticated arbitrary file disclosure via `/attachment/preview/{id}` and `/pic/preview/{id}`1Panel-dev CordysCRM
CVE-2026-76901CordysCRM: Broken object-level authorization in lead pool and account pool detail endpoints exposes arbitrary leads and…1Panel-dev CordysCRM
CVE-2026-76900CordysCRM: SSRF via Approval Flow Webhook Execution due to Missing SSRF Validation at Runtime1Panel-dev CordysCRM
CVE-2026-76899CordysCRM: Authenticated SQL injection via `sort.name` on `POST /account-pool/page`1Panel-dev CordysCRM
CVE-2026-69129KubePi: Insufficient per-cluster authorization checks in cluster management APIs1Panel-dev KubePi
CVE-2026-65956KubePi: Unauthenticated SSO/OIDC configuration allows admin account takeover and SSRF1Panel-dev KubePi
CVE-2026-64870MaxKB: UpdateStoreTool fetches caller-supplied app-store URLs without host validation1Panel-dev MaxKB
CVE-2026-63647CordysCRM SSE Notification Stream Hijack via `/sse/subscribe`1Panel-dev CordysCRM
CVE-2026-63646CordysCRM MCP Form Configuration Endpoint Exposed to Anonymous Users1Panel-dev CordysCRM
CVE-2026-61081Panel-dev MaxKB Model Context Protocol Node base_mcp_node.py execute os command injection1Panel-dev MaxKB
CVE-2026-61071Panel-dev MaxKB ChatHeadersMiddleware chat_headers_middleware.py cross site scripting1Panel-dev MaxKB
CVE-2026-61061Panel-dev MaxKB Public Chat static_headers_middleware.py StaticHeadersMiddleware cross site scripting1Panel-dev MaxKB
CVE-2026-56779MaxKB < 2.10.0 - Server-Side Request Forgery via downloadCallbackUrl and download_url Parameters1Panel-dev MaxKB
CVE-2026-54149MaxKB MCP tool import validation bypass allows post-authentication remote code execution1Panel-dev MaxKB
CVE-2026-52745CordysCRM: Customer Public Pool Sorting Field SQL Injection1Panel-dev CordysCRM
CVE-2026-45413MaxKB: Unsalted MD5 Password Hashing1Panel-dev MaxKB
CVE-2026-45412MaxKB: Unauthenticated SSRF via Workflow Template Import1Panel-dev MaxKB
CVE-2026-44847MaxKB: Webhook Trigger Authentication Bypass1Panel-dev MaxKB
CVE-2026-42337MaxKB: Broken Access Control in MaxKB OSS URL Fetch API1Panel-dev MaxKB
CVE-2026-42336MaxKB: SSRF Bypass via DNS Rebinding in MaxKB OSS URL Fetch1Panel-dev MaxKB
CVE-2026-42335MaxKB: SSRF Bypass in MaxKB OSS URL Fetch due to URL Parsing Discrepancy1Panel-dev MaxKB
CVE-2026-39426MaxKB: Stored XSS via Unsanitized iframe_render Parsing1Panel-dev MaxKB
CVE-2026-39425MaxKB: Stored XSS via Unsanitized html_rander Tags in Markdown Rendering1Panel-dev MaxKB
CVE-2026-39424MaxKB has CSV Injection in its Application Chat Export Functionality1Panel-dev MaxKB
CVE-2026-39423Stored XSS via Eval Injection in EchartsRander Component1Panel-dev MaxKB
CVE-2026-39422MaxKB has Stored XSS via ChatHeadersMiddleware1Panel-dev MaxKB
CVE-2026-39421MaxKB: Sandbox escape via ctypes and unhooked SYS_pkey_mprotect1Panel-dev MaxKB
CVE-2026-39420MaxKB: Sandbox escape via LD_PRELOAD bypass1Panel-dev MaxKB
CVE-2026-39419MaxKB: Sandbox Result Validation Bypass via Tool Output Spoofing1Panel-dev MaxKB
CVE-2026-39418MaxKB: SSRF via sandbox network hook bypass1Panel-dev MaxKB
CVE-2026-39417MaxKB: RCE via MCP stdio command injection in workflow engine1Panel-dev MaxKB
CVE-2026-235251panel App Store vulnerable to Cross-site Scripting1Panel-dev 1Panel
CVE-2026-162231Panel-dev CordysCRM Third Party Edit Endpoint IntegrationConfigService.java getSqlBotSrc server-side request forgery1Panel-dev CordysCRM
CVE-2026-162221Panel-dev CordysCRM Third Party Endpoint TokenService.java server-side request forgery1Panel-dev CordysCRM
CVE-2026-105671Panel-dev CordysCRM ModuleFormController ModuleFormService.java save cross site scripting1Panel-dev CordysCRM
CVE-2026-105141Panel-dev CordysCRM RequestParamTrimConfig.java cross site scripting1Panel-dev CordysCRM
CVE-2025-665081Panel IP Access Control Bypass via Untrusted X-Forwarded-For Headers1Panel-dev 1Panel
CVE-2025-665071Panel – CAPTCHA Bypass via Client-Controlled Flag1Panel-dev 1Panel
CVE-2025-66446MaxKB has a Python sandbox LD_PRELOAD bypass1Panel-dev MaxKB
CVE-2025-66419MaxKB vulnerable to privilege escalation through sandbox bypass1Panel-dev MaxKB
CVE-2025-64703MaxKB has Information Leak in sandbox1Panel-dev MaxKB
CVE-2025-64511MaxKB has SSRF in sandbox1Panel-dev MaxKB
CVE-2025-544241Panel Agent Bypasses Certificate Verification Leading to Arbitrary Command Execution1Panel-dev 1Panel
CVE-2025-53928MaxKB has RCE in MCP call1Panel-dev MaxKB
CVE-2025-53927MaxKB sandbox bypass1Panel-dev MaxKB
CVE-2025-48950MaxKB Python Sandbox Bypass in Function Library1Panel-dev MaxKB
CVE-2025-45461Panel-dev MaxKB Knowledge Base Module csv injection1Panel-dev MaxKB
CVE-2025-32383MaxKB has a reverse shell vulnerability in function library1Panel-dev MaxKB
CVE-2025-156321Panel-dev MaxKB MdPreview chat.ts cross site scripting1Panel-dev MaxKB
CVE-2025-104331Panel-dev MaxKB debug deserialization1Panel-dev MaxKB
CVE-2024-56137MaxKB RCE vulnerability in function library1Panel-dev MaxKB
CVE-2024-399111Panel SQL injection1Panel-dev 1Panel
CVE-2024-39907a sqlinjection in 1Panel1Panel-dev 1Panel
CVE-2024-36111KubePi's JWT token validation has a defect1Panel-dev KubePi
CVE-2024-34352Arbitrary file write vulnerability in 1Panel1Panel-dev 1Panel
CVE-2024-302571Panel's password verification is suspected to have a timing attack vulnerability1Panel-dev 1Panel
CVE-2024-272881Panel open source panel project has an unauthorized vulnerability.1Panel-dev 1Panel
CVE-2024-247681Panel set-cookie is missing the Secure keyword1Panel-dev 1Panel
CVE-2023-399661Panel arbitrary file write vulnerability exists in the background1Panel-dev 1Panel
CVE-2023-399651Panel Unauthorized access in Backend1Panel-dev 1Panel
CVE-2023-399641Panel O&M management panel has a background arbitrary file reading vulnerability1Panel-dev 1Panel
CVE-2023-37917Privilege Escalation in kubepi1Panel-dev KubePi
CVE-2023-37916Leak password hash of any user1Panel-dev KubePi
CVE-2023-37477Command injection in firewall ip functionality in 1Panel1Panel-dev 1Panel
CVE-2023-364581Panel vulnerable to ommand injection when entering the container terminal1Panel-dev 1Panel
CVE-2023-364571Panel vulnerable to command injection when adding container repositories1Panel-dev 1Panel

66 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.