Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ajenti

First CVE: Apr 30, 2014Active for: 12 yearsTotal CVEs: 13
35.6
VTI Score
Medium

Ajenti is a modestly represented, server-management and system-administration platform whose vulnerability footprint, despite a narrow product scope, ranks among more prominent vendors in the landscape. Vulnerabilities affecting the platform cluster around web-application and authentication-layer weaknesses—cross-site scripting, improper authentication, race conditions, and cross-site request forgery—that are characteristic of remotely accessible administration interfaces, and frequently acquire public exploit code. A meaningful share of the vendor's disclosures reach critical severity, reflecting the elevated privilege and broad system access that these vulnerabilities can confer on an attacker. Defenders should treat Ajenti instances, particularly internet-facing or exposed administrative panels, as high-priority patching targets; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ajenti over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 30, 2014
12 years ago
Most Recent CVE
Apr 10, 2026
105 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-25066HIGH
A vulnerability has been found in ajenti 2.1.31 and classified as critical. This vulnerability affects unknown code of the component API. The manipulation leads to privilege escala
Jun 9, 20228.840NOYES
CVE-2026-27975CRITICAL
Ajenti is a Linux and BSD modular server admin panel. Prior to version 2.2.13, an unauthenticated user could gain access to a server to execute arbitrary code on this server. This
Feb 26, 20269.832NONO
CVE-2018-18548MEDIUM
ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in File Manager.
Oct 24, 20186.132NOYES
CVE-2026-40177HIGH
ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible to bypass the password authenticat
Apr 10, 20267.527NONO
CVE-2018-1000082HIGH
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code exe
Mar 13, 20188.827NONO
CVE-2026-40178MEDIUM
ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible during a short moment after the au
Apr 10, 20265.922NONO
CVE-2026-35175MEDIUM
Ajenti is a Linux and BSD modular server admin panel. Prior to 2.2.15, an authenticated user (using the auth_users plugin authentication method) could install a custom package even
Apr 6, 20266.522NONO
CVE-2018-1000126HIGH
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti
Mar 13, 20187.522NONO
CVE-2018-1000081HIGH
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable
Mar 13, 20187.522NONO
CVE-2018-1000080MEDIUM
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear
Mar 13, 20186.520NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
46%
38%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (84.6%)
Unknown2 (15.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (76.9%)
High1 (7.7%)
Unknown2 (15.4%)
User Interaction
None9 (69.2%)
Unknown2 (15.4%)
Required2 (15.4%)
Privileges Required
Low3 (23.1%)
High0 (0.0%)
None8 (61.5%)
Unknown2 (15.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
7.7% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
7.7% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ajenti.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ajenti — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ajenti's Products

View all 3 CNAs →

Top CWEs