Cyberpanel is a web hosting control panel with a niche but strategically exposed deployment footprint, widely used in small-to-medium hosting and server-management environments. Vulnerabilities affecting the product skew strongly toward critical severity and have an elevated tendency toward confirmed in-the-wild exploitation, frequently acquiring public exploit code; the recurring weakness classes—OS command injection, cross-site scripting, missing authentication and authorization controls, and CSRF—expose the control plane itself to remote compromise and lateral movement. Defenders should treat Cyberpanel instances as high-value targets requiring strict access controls, network segmentation, and prioritized patching; live exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cyberpanel over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-51378CRITICAL getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via / | Oct 29, 2024 | 9.8 | 99 | YES | YES |
CVE-2024-51567CRITICAL upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBas | Oct 29, 2024 | 9.8 | 98 | YES | YES |
CVE-2024-51568CRITICAL CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager | Oct 29, 2024 | 9.8 | 75 | NO | YES |
CVE-2026-41473CRITICAL CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbit | Apr 24, 2026 | 9.1 | 34 | NO | NO |
CVE-2024-53376HIGH CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the websites/submitWebsiteCreation URI | Dec 16, 2024 | 8.8 | 33 | NO | NO |
CVE-2019-13056HIGH An issue was discovered in CyberPanel through 1.8.4. On the user edit page, an attacker can edit the administrator's e-mail and password because of the lack of CSRF protection. | Jul 2, 2019 | 8.8 | 27 | NO | NO |
CVE-2026-41472MEDIUM CyberPanel versions prior to 2.4.4 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/callback endpoint lacks authentica | Apr 24, 2026 | 6.1 | 26 | NO | NO |
CVE-2024-54679MEDIUM CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions. | Dec 5, 2024 | 6.5 | 21 | NO | NO |
CVE-2024-56112MEDIUM CyberPanel (aka Cyber Panel) before f0cf648 allows XSS via token or username to plogical/phpmyadminsignin.php. | Dec 16, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cyberpanel.
Media articles that mention a CVE ID that affects a product developed by Cyberpanel — matched by CVE ID, not by vendor name.