Agentejo's vulnerability footprint centers on Cockpit, a modular content management and server-administration platform, which despite a narrow product scope has achieved prominence as a widely deployed infrastructure tool. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the attractive target profile of internet-facing administrative interfaces. The exposure recurs persistently through web-tier input-handling weakness classes—cross-site scripting, SQL injection, unsafe file uploads, cross-site request forgery, and code injection—that are characteristic of application frameworks where user input flows into database queries, template rendering, and code execution contexts. Defenders should prioritize internet-exposed instances of this platform and treat published disclosures as requiring urgent remediation; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Agentejo over time
Signals from CVEs in this vendor scope (31 CVEs).
31 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35847CRITICAL Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function. | Dec 30, 2020 | 9.8 | 93 | NO | YES |
CVE-2020-35846CRITICAL Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function. | Dec 30, 2020 | 9.8 | 90 | NO | YES |
CVE-2020-35848CRITICAL Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function. | Dec 30, 2020 | 9.8 | 85 | NO | YES |
CVE-2020-35131CRITICAL Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated b | Jan 8, 2021 | 9.8 | 70 | NO | YES |
CVE-2022-2713CRITICAL Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0. | Aug 8, 2022 | 9.8 | 31 | NO | NO |
CVE-2023-4451MEDIUM Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4. | Aug 20, 2023 | 6.1 | 30 | NO | YES |
CVE-2018-15540CRITICAL Agentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse the file system to unintended locations and/or access arbitra | Oct 15, 2018 | 9.8 | 30 | NO | NO |
CVE-2024-4825CRITICAL A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker could upload fi | May 14, 2024 | 9.8 | 29 | NO | NO |
CVE-2017-14611CRITICAL SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of | Apr 10, 2018 | 9.1 | 29 | NO | NO |
CVE-2023-1313HIGH Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit prior to 2.4.1. | Mar 10, 2023 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (31 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Agentejo.
Media articles that mention a CVE ID that affects a product developed by Agentejo — matched by CVE ID, not by vendor name.