Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Agentejo

First CVE: Apr 10, 2018Active for: 8 yearsTotal CVEs: 31
52.6
VTI Score
TOP TARGET

Agentejo's vulnerability footprint centers on Cockpit, a modular content management and server-administration platform, which despite a narrow product scope has achieved prominence as a widely deployed infrastructure tool. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the attractive target profile of internet-facing administrative interfaces. The exposure recurs persistently through web-tier input-handling weakness classes—cross-site scripting, SQL injection, unsafe file uploads, cross-site request forgery, and code injection—that are characteristic of application frameworks where user input flows into database queries, template rendering, and code execution contexts. Defenders should prioritize internet-exposed instances of this platform and treat published disclosures as requiring urgent remediation; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
31
Total CVEs
More Total CVEs than 97% of tracked vendors
3.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Agentejo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 10, 2018
8 years ago
Most Recent CVE
Mar 18, 2026
131 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-35847CRITICAL
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
Dec 30, 20209.893NOYES
CVE-2020-35846CRITICAL
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.
Dec 30, 20209.890NOYES
CVE-2020-35848CRITICAL
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
Dec 30, 20209.885NOYES
CVE-2020-35131CRITICAL
Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated b
Jan 8, 20219.870NOYES
CVE-2022-2713CRITICAL
Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.
Aug 8, 20229.831NONO
CVE-2023-4451MEDIUM
Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.
Aug 20, 20236.130NOYES
CVE-2018-15540CRITICAL
Agentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse the file system to unintended locations and/or access arbitra
Oct 15, 20189.830NONO
CVE-2024-4825CRITICAL
A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker could upload fi
May 14, 20249.829NONO
CVE-2017-14611CRITICAL
SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of
Apr 10, 20189.129NONO
CVE-2023-1313HIGH
Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit prior to 2.4.1.
Mar 10, 20238.828NONO
View all 31 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products31 CVEs
52%
23%
26%
Severity distribution among all CVEs352,727 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (3.2%)
Network30 (96.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (48.4%)
Unknown0 (0.0%)
Required16 (51.6%)
Privileges Required
Low10 (32.3%)
High1 (3.2%)
None20 (64.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (31 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
6.5% of CVEs· 98th percentile
Nuclei
6 CVEs
19.4% of CVEs· 97th percentile
ExploitDB
2 CVEs
6.5% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Agentejo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Agentejo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Agentejo's Products

View all 5 CNAs →

Top CWEs