Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cyberpanel

First CVE: Jul 2, 2019Active for: 7 yearsTotal CVEs: 9

Cyberpanel is a web hosting control panel with a niche but strategically exposed deployment footprint, widely used in small-to-medium hosting and server-management environments. Vulnerabilities affecting the product skew strongly toward critical severity and have an elevated tendency toward confirmed in-the-wild exploitation, frequently acquiring public exploit code; the recurring weakness classes—OS command injection, cross-site scripting, missing authentication and authorization controls, and CSRF—expose the control plane itself to remote compromise and lateral movement. Defenders should treat Cyberpanel instances as high-value targets requiring strict access controls, network segmentation, and prioritized patching; live exploitation and severity counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
8.3
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
22.2%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Cyberpanel over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 2, 2019
7 years ago
Most Recent CVE
Apr 24, 2026
92 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-51378CRITICAL
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /
Oct 29, 20249.899YESYES
CVE-2024-51567CRITICAL
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBas
Oct 29, 20249.898YESYES
CVE-2024-51568CRITICAL
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager
Oct 29, 20249.875NOYES
CVE-2026-41473CRITICAL
CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbit
Apr 24, 20269.134NONO
CVE-2024-53376HIGH
CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the websites/submitWebsiteCreation URI
Dec 16, 20248.833NONO
CVE-2019-13056HIGH
An issue was discovered in CyberPanel through 1.8.4. On the user edit page, an attacker can edit the administrator's e-mail and password because of the lack of CSRF protection.
Jul 2, 20198.827NONO
CVE-2026-41472MEDIUM
CyberPanel versions prior to 2.4.4 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/callback endpoint lacks authentica
Apr 24, 20266.126NONO
CVE-2024-54679MEDIUM
CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.
Dec 5, 20246.521NONO
CVE-2024-56112MEDIUM
CyberPanel (aka Cyber Panel) before f0cf648 allows XSS via token or username to plogical/phpmyadminsignin.php.
Dec 16, 20246.118NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
33%
22%
44%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (66.7%)
Unknown0 (0.0%)
Required3 (33.3%)
Privileges Required
Low2 (22.2%)
High0 (0.0%)
None7 (77.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
2 CVEs
22.2% of CVEs· 100th percentile
Metasploit
3 CVEs
33.3% of CVEs· 99th percentile
Nuclei
3 CVEs
33.3% of CVEs· 98th percentile
ExploitDB
1 CVE
11.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cyberpanel.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cyberpanel — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cyberpanel's Products

View all 2 CNAs →

Top CWEs